CVE-2026-76658
nicheUnauthenticated SSH flaw in HPE Aruba Fabric Composer allows admin takeover
HPE Aruba Fabric Composer (AFC) contains an improper authentication flaw (CWE-287) in its SSH daemon that allows an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. The flaw is triggered simply by connecting to the SSH service exposed by the Fabric Composer host over the network, with no credentials or user interaction required. A successful attacker can execute arbitrary commands as a privileged user on the underlying operating system, leading to complete compromise of the AFC management host. Any organization running HPE Aruba Fabric Composer — orchestration software typically deployed in enterprise and data center environments — is potentially affected, though exposure depends on whether the SSH daemon is reachable from untrusted networks. As of now there is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS puts 30-day exploitation probability at only 0.4%, so no active exploitation is known.
What to do: Restrict SSH access to Fabric Composer hosts so only trusted management networks can reach the SSH daemon, and monitor the HPE/Aruba security advisory for the patched release, since affected and fixed version numbers are not stated in this data. Once HPE publishes a fix, upgrade affected AFC hosts promptly; meanwhile treat any AFC host whose SSH port is reachable from untrusted networks as at risk.
| HPE (Aruba Networks) Aruba Fabric Composer (AFC) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.