Description
A local privilege escalation vulnerability in HPE Networking Fabric Composer could allow an authenticated privileged user on the underlying host to elevate their user privileges to those of a higher role. A successful exploit allows the attacker to change the state of certain settings of the affected system.
Published: 2026-09-01
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Assess
AI Analysis

Impact

A local privilege escalation vulnerability exists in HPE Networking Fabric Composer, allowing an authenticated privileged user on the underlying host to raise their privileges to a higher role. The vulnerability is classified as CWE‑269, improper privilege assignment. In a successful exploitation, the attacker can modify the state of certain system settings, potentially affecting the integrity of the system configuration and undermining the intended separation of duties.

Affected Systems

The affected product is Hewlett Packard Enterprise Fabric Composer. No specific version range is provided, indicating that all deployed instances of Fabric Composer may be susceptible until a vendor‑issued fix is applied.

Risk and Exploitability

The CVSS score of 4.4 denotes moderate severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be local; an attacker must already have authenticated privileged access on the host. With this access, the attacker can elevate privileges and change configuration settings, but no remote exploitation is indicated. The overall risk is moderate, primarily impacting the integrity of system configurations and potentially facilitating broader lateral movement if higher privileges are gained.

Generated by OpenCVE AI on September 2, 2026 at 01:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any HPE‑issued patch or upgrade Fabric Composer to a version that addresses the vulnerability.
  • Restrict local user privileges, ensuring that only trusted personnel hold higher‐level roles and permissions.
  • Monitor system configuration and audit logs for unauthorized changes to detect potential exploitation.

Generated by OpenCVE AI on September 2, 2026 at 01:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A local privilege escalation vulnerability in HPE Networking Fabric Composer could allow an authenticated privileged user on the underlying host to elevate their user privileges to those of a higher role. A successful exploit allows the attacker to change the state of certain settings of the affected system.
Title Local Privilege Escalation in HPE Networking Fabric Composer
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:48.177Z

Reserved: 2026-08-13T16:38:10.812Z

Link: CVE-2026-73740

cve-icon Vulnrichment

Updated: 2026-09-01T20:13:33.648Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:21.640

Modified: 2026-09-03T15:12:25.217

Link: CVE-2026-73740

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:44:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management