Description
An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary commands on the underlying operating system, leading to complete compromise of the affected system.
Published: 2026-09-01
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an arbitrary file write exposed through the Fabric Composer API that can be leveraged by a logged‑in operator with low privilege to write files anywhere on the system. By creating malicious files such as executables or scripts, the attacker can then trigger those files to run under the operating system’s context, effectively achieving remote code execution and a full compromise of the device.

Affected Systems

All HPE Networking Fabric Composer deployments where the API is enabled and accessible to operator accounts are affected. The issue is specific to HPE Fabric Composer as identified by Hewlett Packard Enterprise.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity flaw. Because the vulnerability requires authentication, attackers must first compromise or use legitimate operator credentials, which may be limited in scope. The EPSS score is not available, so the current probability of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog; however, the ability to obtain remote code execution on a networking device is a critical concern, especially in environments that expose the API externally.

Generated by OpenCVE AI on September 2, 2026 at 01:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the HPE patch published in the referenced HPE support article immediately.
  • Revoke operator permissions that allow API access or restrict those actions to only administrator accounts.
  • Configure network controls or firewall rules to block or limit external access to the Fabric Composer API until the patch is applied.

Generated by OpenCVE AI on September 2, 2026 at 01:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary commands on the underlying operating system, leading to complete compromise of the affected system.
Title Authenticated Arbitrary File Write leads to Remote Code Execution in HPE Networking Fabric Composer
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:19.789Z

Reserved: 2026-08-13T16:35:39.126Z

Link: CVE-2026-73705

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T20:17:17.870

Modified: 2026-09-01T21:08:28.570

Link: CVE-2026-73705

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T01:30:20Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')