Junglewise Threat Intelligence

CVE-2026-73747: HPE Networking Fabric Composer privilege escalation

CVE-2026-73747 · Severity: low · CVSS 2.5 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a management platform for HPE network switches and fabric components. A vulnerability allows authenticated users with limited local access to escalate their privileges on the system, potentially enabling them to make unauthorized configuration changes to network infrastructure.

Technical details

This is a local privilege-escalation vulnerability in HPE Networking Fabric Composer. The vulnerability requires an authenticated low-privilege operator user with local access to the system to exploit. Successful exploitation allows an attacker to escalate their privileges and make limited modifications to the affected system. A patch is likely available via HPE support.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats