Description
A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user with local access to elevate their user privileges and make limited modifications on the affected system.
Published: 2026-09-01
Score: 2.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Assess Impact
AI Analysis

Impact

The vulnerability in HPE Networking Fabric Composer permits an authenticated low‑privilege operator who has local access to elevate their privileges, enabling them to perform limited modifications on the affected system.

Affected Systems

The flaw affects Hewlett Packard Enterprise’s Fabric Composer product. Versions of the software distributed by HPE that do not include the vendor‑issued patch are vulnerable.

Risk and Exploitability

With a CVSS score of 2.5 the severity is low, and the EPSS score is not available, indicating no known widespread exploitation. The attack vector is local and requires authentication, so the risk is confined to individuals who already possess a low‑privilege user account. The vulnerability does not provide full system control, but it can be used to add or change configuration settings or install restricted software within the local environment. The flaw is not listed in CISA’s KEV catalog, suggesting no publicly known exploits.

Generated by OpenCVE AI on September 2, 2026 at 01:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the HPE fix for CVE‑2026‑73747 by updating to the latest firmware or software release that contains the patch.
  • Enforce strict access control, limiting local operator accounts to the minimum privileges needed for their tasks.
  • Remove or disable unused local services and applications that could be abused by low‑privilege users.

Generated by OpenCVE AI on September 2, 2026 at 01:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user with local access to elevate their user privileges and make limited modifications on the affected system.
Title Local Privilege Escalation Vulnerability in HPE Networking Fabric Composer
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 2.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:54.973Z

Reserved: 2026-08-13T16:38:10.813Z

Link: CVE-2026-73747

cve-icon Vulnrichment

Updated: 2026-09-01T20:06:35.678Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:22.440

Modified: 2026-09-02T15:14:22.810

Link: CVE-2026-73747

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:43:55Z

Weaknesses
  • CWE-269

    Improper Privilege Management