Junglewise Threat Intelligence

CVE-2026-73702: HPE Networking Fabric Composer privilege escalation in API

CVE-2026-73702 · Severity: high · CVSS 8.8 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network management platform used to configure and monitor fabric switches and networking infrastructure. A privilege escalation vulnerability in its API allows authenticated low-privilege operators to gain administrative access, potentially enabling complete control of the network management system and the infrastructure it controls.

Technical details

A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer that allows an authenticated low-privilege operator user to escalate their permissions to administrative level. The vulnerability is reachable via the API and requires valid authentication credentials. Successful exploitation grants an attacker complete administrative control over the system, enabling them to modify network configurations, access sensitive data, and potentially compromise the entire managed infrastructure.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats