Executive brief
HPE Networking Fabric Composer's SSH daemon contains a flaw that allows unauthenticated remote attackers to gain administrative access. Successful exploitation enables execution of arbitrary commands with elevated privileges on the underlying system, resulting in complete compromise of the device and potential lateral movement into the broader network infrastructure.
Technical details
The SSH daemon in HPE Networking Fabric Composer contains an authentication bypass vulnerability (CVE-2026-76658) that permits unauthenticated remote attackers to establish administrative sessions. The vulnerability is network-reachable and requires no user interaction or prior authentication. Successful exploitation grants attackers the ability to execute arbitrary commands with root privileges on the underlying operating system, achieving complete system compromise. The vulnerability has a CVSS score of 10.0 reflecting maximum severity across all metrics. Patches are expected to be available through HPE's support channels.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed