Description
A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete system compromise.
Published: 2026-09-01
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privileged Escalation
Action: Patch Now
AI Analysis

Impact

The vulnerability permits a logged‑in low‑privilege operator to gain administrative rights through the Fabric Composer API. As a result, the attacker can launch commands, alter configurations, and fully compromise the fabric network. This flaw falls under improper access control and can be exploited after authentication, providing broad system control to the attacker.

Affected Systems

Affected are HPE Fabric Composer deployments. The specific affected versions are not listed in the advisory, so all releases before the patch should be considered vulnerable.

Risk and Exploitability

With a CVSS score of 8.8, the flaw is classified as high severity. EPSS score indicates a very low exploitation probability (< 1%), and the vulnerability is not in the CISA KEV catalog, suggesting that exploitation is not yet widespread. However, because the attack vector requires prior authentication, organizations must assume that privileged users can potentially abuse the API if not patched or protected. An attacker could likely exploit this by calling privileged API endpoints with elevated permissions.

Generated by OpenCVE AI on September 3, 2026 at 14:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch released in the referenced support article for Fabric Composer that resolves the privilege escalation bug.
  • If a patch is not yet available, restrict API access to only trusted administrators using role‑based access control and network segmentation.
  • Conduct an internal audit of low‑privilege user accounts to confirm no unintended admin roles.

Generated by OpenCVE AI on September 3, 2026 at 14:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
Weaknesses CWE-863
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete system compromise.
Title Authenticated Privilege Escalation Vulnerability in the API of HPE Networking Fabric Composer
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T15:24:09.947Z

Reserved: 2026-08-13T16:35:39.126Z

Link: CVE-2026-73702

cve-icon Vulnrichment

Updated: 2026-09-02T15:12:59.938Z

cve-icon NVD

Status : Modified

Published: 2026-09-01T20:17:17.557

Modified: 2026-09-02T16:17:19.780

Link: CVE-2026-73702

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T14:30:05Z

Weaknesses