Description
A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
Published: 2026-09-01
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

A flaw in the HPE Networking Fabric Composer API permits an unauthenticated attacker to execute arbitrary commands on the underlying host, provided that conditions beyond the attacker’s control exist. This remote code execution vulnerability can lead to complete system compromise, including unauthorized data access, modification, or deletion, and can serve as a pivot for further attacks within the network.

Affected Systems

The vulnerability affects the Hewlett Packard Enterprise Fabric Composer product. No specific affected version information is supplied in the advisory, so all installations of Fabric Composer should be verified for the presence of the issued fix.

Risk and Exploitability

The CVSS base score is 8.1, indicating a high severity risk. EPSS score is < 1%, indicating a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred as network‑based exposure to the Composer API, and the preconditions required lie outside the attacker’s control, meaning exploitation may be limited to environments where the API is publicly exposed and the underlying host’s configuration allows command execution.

Generated by OpenCVE AI on September 3, 2026 at 16:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑issued patch or update for HPE Fabric Composer that addresses the API remote code execution flaw.
  • Configure the Fabric Composer API to enforce authentication or restrict access to internal networks only.
  • Block external access to the Composer API using firewall rules or network segmentation.

Generated by OpenCVE AI on September 3, 2026 at 16:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77

Wed, 02 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
Weaknesses CWE-78
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
Title Unauthenticated Remote Code Execution in HPE Networking Fabric Composer API
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-03T14:10:29.886Z

Reserved: 2026-08-13T16:36:38.746Z

Link: CVE-2026-73712

cve-icon Vulnrichment

Updated: 2026-09-02T13:53:03.496Z

cve-icon NVD

Status : Modified

Published: 2026-09-01T20:17:18.610

Modified: 2026-09-03T15:17:32.457

Link: CVE-2026-73712

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T17:00:06Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')