Junglewise Threat Intelligence

CVE-2026-73711: HPE Networking Fabric Composer privilege escalation in API endpoint

CVE-2026-73711 · Severity: high · CVSS 8.1 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network management platform used to orchestrate and manage fabric switches and networking infrastructure. A privilege escalation vulnerability in its API endpoint allows unauthenticated remote attackers to gain administrative privileges, resulting in complete compromise of the management host and potential control over the entire network fabric.

Technical details

A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer that permits unauthenticated access. The vulnerability allows a remote attacker to bypass authentication mechanisms and gain administrative privileges without valid credentials. The attack vector is network-accessible, requiring only the ability to reach the API endpoint. Successful exploitation results in full administrative access to the Fabric Composer host, enabling attackers to modify network configurations, access sensitive data, and potentially compromise connected network infrastructure.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats