Junglewise Threat Intelligence

CVE-2026-19766: HPE Networking Fabric Composer authentication bypass in OS

CVE-2026-19766 · Severity: critical · CVSS 9.6 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network management platform that controls fabric switches and infrastructure. An authentication bypass vulnerability in its underlying operating system allows unauthenticated attackers on the same network segment to execute code with system privileges, potentially gaining complete control of the management host and all connected network equipment.

Technical details

This is an authentication bypass vulnerability in the underlying operating system of HPE Networking Fabric Composer. An unauthenticated adjacent attacker can exploit this flaw to achieve arbitrary code execution with privileged user rights on the OS layer. The attack vector is adjacent network access (same network segment), requiring no prior authentication. Successful exploitation results in complete compromise of the AFC host, including potential control over managed fabric infrastructure. Patches are expected to be available through HPE security advisories.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed: CVE-2026-19766 published

References

Related threats