Description
Command injection vulnerabilities in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated remote attacker to perform command injection against the affected system. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Published: 2026-09-01
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution with elevated privileges
Action: Apply Patch
AI Analysis

Impact

Command injection vulnerabilities exist in the web‑based management interface of HPE Fabric Composer. An attacker who has authenticated to the interface can insert arbitrary operating‑system commands, which are then executed with the privileges of the web service. This enables the attacker to read, modify, or delete data, install malware, or disrupt services, thereby compromising confidentiality, integrity, and availability of the fabric environment.

Affected Systems

The affected product is Hewlett Packard Enterprise Fabric Composer. The advisory does not specify affected software versions or build numbers; therefore the vulnerability is likely present in all released versions of the device’s web‑based management interface that have not yet been patched.

Risk and Exploitability

The CVSS score of 7.2 indicates moderate to high risk, while the EPSS score is < 1%, leaving the likelihood of exploitation uncertain. The vulnerability is not listed in CISA’s KEV catalog, which suggests no widespread exploitation has been reported. The attack requires a valid authenticated session to the management interface; once authenticated, the attacker can execute arbitrary system commands. This combination of authentication requirement and remote execution grants powerful capabilities to an attacker who can compromise credentials or use a privileged account.

Generated by OpenCVE AI on September 3, 2026 at 14:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the HPE support site or the advisory link for an official patch for Fabric Composer and apply it promptly.
  • If a patch is not yet available, restrict web‑based management access to trusted administrators, enforce strong, role‑based authentication, and, when possible, disable the web interface entirely or place it behind a secure VPN.
  • Continuously monitor system and application logs for unusual command execution patterns or unauthorized administrative activity, and configure alerts for suspicious events.

Generated by OpenCVE AI on September 3, 2026 at 14:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Command injection vulnerabilities in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated remote attacker to perform command injection against the affected system. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Title Authenticated Command Injection Vulnerabilities in HPE Networking Fabric Composer Web-Based Management Interface
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T15:29:38.712Z

Reserved: 2026-08-13T16:37:06.403Z

Link: CVE-2026-73722

cve-icon Vulnrichment

Updated: 2026-09-02T15:29:25.527Z

cve-icon NVD

Status : Modified

Published: 2026-09-01T20:17:19.730

Modified: 2026-09-02T16:17:21.090

Link: CVE-2026-73722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T14:30:05Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')