Description
A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges, leading to a complete compromise of the affected host.
Published: 2026-09-01
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation Leading to Arbitrary Code Execution
Action: Immediate Patch
AI Analysis

Impact

A local privilege‑escalation flaw in HPE Networking Fabric Composer permits a legitimate local user or process to gain root privileges and execute arbitrary code on the compromised host. The vulnerability allows the attacker to alter system configuration, exfiltrate data, and gain full control of the machine. The core weakness is a failure to enforce proper access controls, enabling an internal user to bypass authorization checks.

Affected Systems

The vulnerability affects the Hewlett Packard Enterprise Fabric Composer product. Specific release versions are not enumerated in the advisory, so all supported releases of Fabric Composer are considered at risk until a patch is applied.

Risk and Exploitability

The CVSS score of 7 indicates a high severity. The EPSS score of 0.00086 (<1%) indicates a very low exploitation probability. The issue is not listed in the CISA KEV catalog, implying that widespread exploitation has not yet been observed. The attack requires local access, meaning an attacker must already have a foothold on the system; however, once local access is achieved, the flaw enables full root‑level execution.

Generated by OpenCVE AI on September 3, 2026 at 16:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE Fabric Composer security patch from the official HPE support site.
  • Enforce strict local privilege segmentation so that only trusted users can access the Fabric Composer installation directories and processes.
  • Disable or isolate any unused Fabric Composer services or modules to reduce the attack surface.

Generated by OpenCVE AI on September 3, 2026 at 16:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges, leading to a complete compromise of the affected host.
Title Local Privilege Escalation leads to Arbitrary Code Execution in HPE Networking Fabric Composer
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T15:31:51.846Z

Reserved: 2026-08-13T16:37:06.403Z

Link: CVE-2026-73725

cve-icon Vulnrichment

Updated: 2026-09-02T15:31:36.524Z

cve-icon NVD

Status : Modified

Published: 2026-09-01T20:17:20.047

Modified: 2026-09-02T16:17:21.450

Link: CVE-2026-73725

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T16:15:06Z

Weaknesses