Junglewise Threat Intelligence

CVE-2026-73705: HPE Networking Fabric Composer arbitrary file write in API

CVE-2026-73705 · Severity: high · CVSS 8.8 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network management and orchestration platform used to configure and monitor fabric-based networking environments. An authenticated operator user can exploit a file write flaw in the API to escalate privileges and execute arbitrary commands, potentially compromising the entire management platform and all connected network infrastructure.

Technical details

The vulnerability is an arbitrary file write flaw in the API of HPE Networking Fabric Composer that allows privilege escalation. An authenticated low-privilege operator user can write arbitrary files through the API, enabling them to escalate to higher privileges and execute arbitrary commands on the underlying operating system. The attack requires valid authentication credentials but no elevated initial privileges. Successful exploitation results in complete system compromise with OS-level command execution.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats