ZeroHour

CVE-2026-76658

niche

Unauthenticated SSH flaw in HPE Aruba Fabric Composer allows admin takeover

CVSS 3.1
10.0 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

HPE Aruba Fabric Composer (AFC) contains an improper authentication flaw (CWE-287) in its SSH daemon that allows an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. The flaw is triggered simply by connecting to the SSH service exposed by the Fabric Composer host over the network, with no credentials or user interaction required. A successful attacker can execute arbitrary commands as a privileged user on the underlying operating system, leading to complete compromise of the AFC management host. Any organization running HPE Aruba Fabric Composer — orchestration software typically deployed in enterprise and data center environments — is potentially affected, though exposure depends on whether the SSH daemon is reachable from untrusted networks. As of now there is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS puts 30-day exploitation probability at only 0.4%, so no active exploitation is known.

What to do: Restrict SSH access to Fabric Composer hosts so only trusted management networks can reach the SSH daemon, and monitor the HPE/Aruba security advisory for the patched release, since affected and fixed version numbers are not stated in this data. Once HPE publishes a fix, upgrade affected AFC hosts promptly; meanwhile treat any AFC host whose SSH port is reachable from untrusted networks as at risk.

Affected
HPE (Aruba Networks) Aruba Fabric Composer (AFC)
Estimated exposure
nicheestimated low thousands of AFC management-host deployments worldwide; unknown precisely — Aruba Fabric Composer is a niche enterprise orchestration tool typically deployed as one management host per data center fabric rather than at internet scale, and no public install-base counts are available for this product.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.