Junglewise Threat Intelligence

CVE-2026-73723: HPE Networking Fabric Composer privilege escalation in web management interface

CVE-2026-73723 · Severity: high · CVSS 7.1 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a web-based management platform for enterprise networking infrastructure. A privilege escalation flaw allows authenticated low-privilege operator users to perform actions reserved for higher-privilege roles, potentially enabling unauthorized network configuration changes and operational disruption.

Technical details

A privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Composer, allowing an authenticated low-privilege operator user to perform state-changing actions beyond their authorization level. The vulnerability requires valid credentials (operator-level access) and network access to the management interface. Successful exploitation enables unauthorized administrative actions on the platform, such as modifying network configuration, user accounts, or system settings. An official patch is expected to be available through HPE support channels.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats