Junglewise Threat Intelligence

CVE-2026-73725: HPE Networking Fabric Composer privilege escalation

CVE-2026-73725 · Severity: high · CVSS 7 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a management platform for enterprise network fabric infrastructure. A local privilege escalation vulnerability allows an authenticated local attacker to execute arbitrary code with root privileges, potentially compromising the entire management host and the networks it controls.

Technical details

This is a local privilege escalation vulnerability in HPE Networking Fabric Composer that permits an attacker with local access to escalate privileges and achieve arbitrary code execution as root. The vulnerability requires local access to the affected system, meaning the attacker must already have some level of system access (e.g., a regular user account or shell access). Successful exploitation results in complete compromise of the host with root-level privileges, enabling modification of system configuration, access to sensitive data, and potential lateral movement to connected network infrastructure.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats