Junglewise Threat Intelligence

CVE-2026-73712: HPE Networking Fabric Composer API remote command execution

CVE-2026-73712 · Severity: high · CVSS 8.1 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network management platform used to configure and administer fabric switches and networking infrastructure. A vulnerability in its API allows unauthenticated attackers to execute arbitrary commands on the underlying host system, potentially compromising the entire management platform and all connected network devices.

Technical details

The vulnerability exists in the API of HPE Networking Fabric Composer and allows remote code execution via an unauthenticated attack vector. The flaw permits an attacker to execute arbitrary commands on the underlying operating system with the privileges of the Fabric Composer service. While the vulnerability requires certain preconditions outside the attacker's control to be met, successful exploitation results in complete system compromise. No authentication is required to trigger the vulnerability.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats