Junglewise Threat Intelligence

CVE-2026-76658: HPE Networking Fabric Composer SSH daemon auth bypass

CVE-2026-76658 · Severity: critical · CVSS 10 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer's SSH daemon contains a flaw that allows unauthenticated remote attackers to gain administrative access. Successful exploitation enables execution of arbitrary commands with elevated privileges on the underlying system, resulting in complete compromise of the device and potential lateral movement into the broader network infrastructure.

Technical details

The SSH daemon in HPE Networking Fabric Composer contains an authentication bypass vulnerability (CVE-2026-76658) that permits unauthenticated remote attackers to establish administrative sessions. The vulnerability is network-reachable and requires no user interaction or prior authentication. Successful exploitation grants attackers the ability to execute arbitrary commands with root privileges on the underlying operating system, achieving complete system compromise. The vulnerability has a CVSS score of 10.0 reflecting maximum severity across all metrics. Patches are expected to be available through HPE's support channels.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats