Description
A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
Published: 2026-09-01
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the HPE Networking Fabric Composer API permits an unauthenticated attacker to execute arbitrary commands on the underlying host, provided that conditions beyond the attacker’s control exist. This remote code execution vulnerability can lead to complete system compromise, including unauthorized data access, modification, or deletion, and can serve as a pivot for further attacks within the network.

Affected Systems

The vulnerability affects the Hewlett Packard Enterprise Fabric Composer product. No specific affected version information is supplied in the advisory, so all installations of Fabric Composer should be verified for the presence of the issued fix.

Risk and Exploitability

The CVSS base score is 8.1, indicating a high severity risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred as network-based exposure to the Composer API, and the preconditions required lie outside the attacker’s control, meaning exploitation may be limited to environments where the API is publicly exposed and the underlying host’s configuration allows command execution.

Generated by OpenCVE AI on September 2, 2026 at 01:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑issued patch or update for HPE Fabric Composer that addresses the API remote code execution flaw.
  • Configure the Fabric Composer API to enforce authentication or restrict access to internal networks only.
  • Block external access to the Composer API using firewall rules or network segmentation.

Generated by OpenCVE AI on September 2, 2026 at 01:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
Title Unauthenticated Remote Code Execution in HPE Networking Fabric Composer API
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:25.252Z

Reserved: 2026-08-13T16:36:38.746Z

Link: CVE-2026-73712

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T20:17:18.610

Modified: 2026-09-01T21:08:28.570

Link: CVE-2026-73712

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T01:30:19Z

Weaknesses

No weakness.