Junglewise Threat Intelligence

CVE-2026-73722: HPE Networking Fabric Composer command injection in management interface

CVE-2026-73722 · Severity: high · CVSS 7.2 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a centralized management platform for enterprise network fabric infrastructure. A command injection vulnerability in its web-based interface allows authenticated users to execute arbitrary commands with elevated privileges on the underlying system, potentially compromising network infrastructure and enabling lateral attacks across managed devices.

Technical details

The vulnerability is a command injection flaw in the web-based management interface of HPE Networking Fabric Composer. It requires authentication to exploit, but allows an authenticated remote attacker to inject and execute arbitrary operating system commands with elevated privileges. The attack vector is network-based through the management interface. Successful exploitation enables arbitrary code execution on the system, which could be leveraged to compromise network configuration, extract sensitive data, or establish persistence. Patch availability information was not detailed in the advisory.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats