Description
An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host.
Published: 2026-09-01
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication bypass exists in the underlying operating system of HPE Networking Fabric Composer. An attacker who is present on an adjacent network segment can exploit this flaw without providing credentials and gain the ability to execute arbitrary code as a privileged operating‑system user. This effectively results in a full compromise of the AFC host, allowing the attacker to control the device, modify configurations, or pivot to other systems on the network.

Affected Systems

The vulnerability affects Hewlett Packard Enterprise's Fabric Composer product. No specific firmware or operating‑system versions are listed in the advisory.

Risk and Exploitability

The CVSS score of 9.6 indicates a critical severity. The exploit requires only adjacency on the network, no authentication, and grants execution of arbitrary code with elevated privileges. There is no EPSS value and the vulnerability is not currently listed in CISA's KEV catalog, but the high CVSS and lack of authentication barrier suggest a realistic threat for exposed or poorly segmented environments.

Generated by OpenCVE AI on September 1, 2026 at 23:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch for HPE Fabric Composer as soon as it becomes available.
  • Apply network segmentation or firewall rules to restrict traffic to the Fabric Composer, ensuring that only authenticated and authorized hosts can reach it.
  • Enforce least privilege on the underlying operating system and monitor logs for suspicious activity or privilege escalation attempts.

Generated by OpenCVE AI on September 1, 2026 at 23:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host.
Title Authentication Bypass leads to Administrative control of adjacent network hosts in HPE Networking Fabric Composer
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:15.187Z

Reserved: 2026-08-13T16:59:42.306Z

Link: CVE-2026-19766

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T20:17:12.760

Modified: 2026-09-01T21:08:28.570

Link: CVE-2026-19766

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T23:45:17Z

Weaknesses