Junglewise Threat Intelligence

CVE-2026-73701: HPE Networking Fabric Composer unauthenticated remote code execution

CVE-2026-73701 · Severity: critical · CVSS 9 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network management platform used to orchestrate fabric configurations across HPE networking infrastructure. An unauthenticated remote attacker can exploit a vulnerability in the underlying operating system to execute arbitrary code with privileged access, completely compromising the management host and potentially the entire managed network infrastructure.

Technical details

An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. The vulnerability allows an unauthenticated remote attacker to execute arbitrary code with privileged user permissions on the underlying operating system. Successful exploitation requires certain preconditions to be met that are outside of the attacker's direct control. An exploit would result in complete compromise of the affected Fabric Composer host, potentially enabling lateral movement and control of managed networking resources.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats