Description
An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the HPE Networking Fabric Composer host.
Published: 2026-09-01
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An unauthenticated remote code execution flaw exists in the underlying operating system of HPE Networking Fabric Composer. The vulnerability can be triggered only when certain preconditions outside the attacker’s control are satisfied. If an attacker succeeds, they can run arbitrary code with privileged operating‑system rights, resulting in a full compromise of the Fabric Composer host and all data and services running on it. The CVSS base score of 9 indicates a critical impact to confidentiality, integrity, and availability.

Affected Systems

The affected systems are HPE Networking Fabric Composer devices. No specific version information was provided, so all current and future releases must be considered potentially vulnerable until an official patch is applied.

Risk and Exploitability

Because the vulnerability is remote and unauthenticated, an attacker can target the device from outside without needing any credentials. The EPSS score is unavailable, but the high CVSS rating signals a serious risk. The flaw is not yet listed in the CISA KEV catalog, which suggests there are no confirmed widespread exploit incidents at the time of this analysis. However, the potential for complete system takeover warrants a high priority response. The exact attack vector requires that the preconditions be met, but once met, exploitation can occur via normal network traffic handled by the Fabric Composer’s operating system.

Generated by OpenCVE AI on September 2, 2026 at 01:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update HPE Networking Fabric Composer to the latest firmware or patch that addresses CVE‑2026‑73701.
  • Re‑configure exposed network interfaces to prevent unauthorized access, preferably isolating management traffic on a separate, secure subnet.
  • Enforce authentication for all Fabric Composer management services and verify that authentication is properly configured on all relevant endpoints.

Generated by OpenCVE AI on September 2, 2026 at 01:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78
CWE-94

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the HPE Networking Fabric Composer host.
Title Unauthenticated Remote Code Execution in HPE Networking Fabric Composer
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T15:12:20.523Z

Reserved: 2026-08-13T16:35:39.126Z

Link: CVE-2026-73701

cve-icon Vulnrichment

Updated: 2026-09-02T15:12:10.364Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:17.453

Modified: 2026-09-02T16:24:51.110

Link: CVE-2026-73701

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T21:39:11Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')