Junglewise Threat Intelligence

CVE-2026-73709: HPE Networking Fabric Composer OS command injection

CVE-2026-73709 · Severity: high · CVSS 8.3 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a management platform for network fabric infrastructure. A vulnerability in its underlying operating system allows an unauthenticated attacker on the same network segment to execute arbitrary commands on the host system, potentially compromising the integrity and availability of the entire fabric management layer.

Technical details

The vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and can be exploited by an unauthenticated adjacent attacker to execute arbitrary commands. The attack requires certain preconditions outside of the attacker's control. An attacker with network adjacency (same network segment) can leverage this to gain command execution on the underlying host, leading to complete system compromise. The exact vulnerable component and root cause are not disclosed in the available advisory text.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats