Description
A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated remote attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.
Published: 2026-09-01
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

A flaw in the API endpoint of HPE Networking Fabric Composer allows an unauthenticated remote attacker to obtain administrative privileges, effectively granting full control over the host. The vulnerability is a case of improper privilege management (CWE-269) that permits privilege escalation without authentication. Successful exploitation results in the attacker gaining complete administrative access, able to modify settings, deploy malicious code, or exfiltrate data. The impact is high, as it turns an unauthenticated user into a fully privileged attacker.

Affected Systems

The affected product is Hewlett Packard Enterprise Networking Fabric Composer. No specific version range is provided in the advisory, so all installations of Fabric Composer should be reviewed for potential exposure.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. EPSS score is < 1%, indicating very low probability of exploitation, and the vulnerability is not yet listed in the CISA KEV catalog. The attack vector is inferred to be remote, exploiting an unauthenticated API endpoint; no local or physical access prerequisites are mentioned. Given the lack of authentication requirements, the potential for exploitation is significant if the API is reachable from untrusted networks.

Generated by OpenCVE AI on September 3, 2026 at 15:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE Networking Fabric Composer patch or update to a version where the API requires authentication.
  • Restrict or disable network exposure of the vulnerable API endpoint, for example by firewalling or isolating the Fabric Composer service.
  • Monitor Fabric Composer logs for abnormal API activity and enforce strict access controls.

Generated by OpenCVE AI on September 3, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-640

Wed, 02 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-640

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated remote attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.
Title Unauthenticated Privilege Escalation allows Administrative Access in HPE Networking Fabric Composer API
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T14:16:24.205Z

Reserved: 2026-08-13T16:36:38.746Z

Link: CVE-2026-73711

cve-icon Vulnrichment

Updated: 2026-09-02T14:16:09.051Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:18.510

Modified: 2026-09-02T16:16:57.783

Link: CVE-2026-73711

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:30:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management