Junglewise Threat Intelligence

CVE-2026-73729: HPE Networking Fabric Composer privilege escalation in underlying OS

CVE-2026-73729 · Severity: medium · CVSS 6.5 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network fabric management platform used to configure and monitor enterprise network infrastructure. A vulnerability in its underlying operating system could allow an authenticated low-privilege operator with local access to view sensitive information beyond their authorization level, potentially enabling further unauthorized access to network configuration and data.

Technical details

This vulnerability exists in the underlying operating system layer of HPE Networking Fabric Composer. An authenticated low-privilege operator user with local access to upstream AFC (Automation Framework Components) dependencies can exploit insufficient privilege isolation to read sensitive information and data that should be restricted to higher-privilege users. The attack requires prior authentication and local system access. Successful exploitation allows privilege escalation to access unauthorized data, which could serve as a pivot point for further attacks on the network fabric infrastructure. HPE has released security guidance (hpesbnw05133en_us) addressing this vulnerability.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats