Description
An arbitrary file write vulnerability exists in the API of HPE Networking Fabric Composer and could allow an authenticated administrative user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.
Published: 2026-09-01
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Assess Impact
AI Analysis

Impact

An API in HPE Networking Fabric Composer allows an authenticated administrative user to write files anywhere in the underlying filesystem, potentially overwriting critical system files. By exploiting this flaw the attacker can elevate privileges and execute arbitrary system commands with root privileges, resulting in full remote code execution. The CVSS score of 7.2 indicates moderate to high severity for this capability.

Affected Systems

The vulnerability affects all deployments of Hewlett Packard Enterprise Fabric Composer that expose the administrative API. No specific product version is listed, so any installation of Fabric Composer should be reviewed for this flaw until a confirmed fix is available.

Risk and Exploitability

The risk level is medium to high. Although the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalogue, the ability to write arbitrary files and run system commands at root is a compelling objective for both insiders and attackers who compromise administrative credentials. The likely attack vector is via the privileged API, and the vulnerability can be exploited by an authenticated administrator.

Generated by OpenCVE AI on September 3, 2026 at 15:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE Networking Fabric Composer firmware or software version that contains the correction for the arbitrary file write flaw.
  • Reconfigure the API access control to restrict file write operations, ensuring that only pre-approved directories are writable and that path manipulation is sanitized.
  • Enforce strict operating system permissions for the Fabric Composer process, ensuring it runs with the minimum necessary privileges and preventing arbitrary writes to system files.

Generated by OpenCVE AI on September 3, 2026 at 15:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
CWE-275

Wed, 02 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-73
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
CWE-275

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description An arbitrary file write vulnerability exists in the API of HPE Networking Fabric Composer and could allow an authenticated administrative user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.
Title Authenticated Arbitrary File Write Vulnerability leads to Remote Code Execution in HPE Networking Fabric Composer
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T15:27:02.185Z

Reserved: 2026-08-13T16:36:38.746Z

Link: CVE-2026-73719

cve-icon Vulnrichment

Updated: 2026-09-02T15:26:52.970Z

cve-icon NVD

Status : Modified

Published: 2026-09-01T20:17:19.407

Modified: 2026-09-02T16:17:20.730

Link: CVE-2026-73719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:45:05Z

Weaknesses