Description
Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Published: 2026-09-01
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an insecure handling of files within the HPE Networking Fabric Composer API. If an authenticated user sends malformed or malicious file requests, the system may act on them with privileged operating‑system rights, allowing the attacker to run arbitrary commands. The flaw directly enables code execution without needing additional privilege escalation beyond the authenticated session.

Affected Systems

Hewlett Packard Enterprise Fabric Composer is affected. No specific version information is provided, so all releases that include the vulnerable API routes are at risk until a patch is applied.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity, and the EPSS score of 0.00646 (approximately 0.646%) suggests a very low but non‑zero probability of exploitation. The lack of inclusion in CISA’s KEV catalog does not reduce the risk of exploitation. The requirement for authentication means the adversary must compromise or insert a legitimate user account, after which the attacker can leverage the API to perform file operations that lead to execution of arbitrary code. The likely attack vector is an authenticated remote attacker submitting specially crafted file manipulation requests to the API endpoints.

Generated by OpenCVE AI on September 3, 2026 at 14:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE Fabric Composer patch or upgrade to a version where the file handling issue is resolved.
  • Restrict API access to trusted accounts and enforce least‑privilege permissions on file operations.
  • Add input validation and path sanitization before processing file requests to block unauthorized file access.

Generated by OpenCVE AI on September 3, 2026 at 14:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-73
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
Weaknesses CWE-78
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
CWE-284

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Title Authenticated Insecure File Handling allows Remote Code Execution in HPE Networking Fabric Composer API
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T15:27:51.347Z

Reserved: 2026-08-13T16:37:06.403Z

Link: CVE-2026-73720

cve-icon Vulnrichment

Updated: 2026-09-02T15:27:48.738Z

cve-icon NVD

Status : Modified

Published: 2026-09-01T20:17:19.513

Modified: 2026-09-02T16:17:20.853

Link: CVE-2026-73720

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T14:15:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-284

    Improper Access Control

  • CWE-73

    External Control of File Name or Path

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')