Description
A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.
Published: 2026-09-01
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the SSH daemon of HPE Networking Fabric Composer. It permits an attacker without authentication to gain administrative privileges and execute arbitrary commands on the underlying operating system. This grants full control over the affected Fabric Composer host, potentially compromising entire network infrastructures.

Affected Systems

Hewlett Packard Enterprise Fabric Composer devices are affected. No specific version range is listed, so all deployments of the default Fabric Composer SSH daemon should be considered vulnerable until the vendor releases a fix.

Risk and Exploitability

The CVSS score of 10 indicates critical severity. The EPSS score is not available, but the lack of a KEV listing does not reduce the risk of exploitation. The likely attack vector is remote unauthenticated access over the network, requiring only the ability to reach the SSH service. Once accessed, an attacker can gain privileged access and carry out arbitrary commands, leading to complete system compromise.

Generated by OpenCVE AI on September 2, 2026 at 02:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or firmware update that addresses the SSH daemon flaw.
  • Configure firewall rules to restrict access to the SSH port (typically 22) to trusted networks only, or temporarily block the port from external sources until remediation is complete.
  • If immediate patching is not possible, consider disabling the SSH service on Fabric Composer hosts until the fix is applied, and monitor the environment for unusual activity.

Generated by OpenCVE AI on September 2, 2026 at 02:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.
Title Unauthenticated Remote Code Execution in HPE Networking Fabric Composer SSH Daemon
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:57.277Z

Reserved: 2026-08-19T16:10:37.083Z

Link: CVE-2026-76658

cve-icon Vulnrichment

Updated: 2026-09-01T20:04:40.578Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:23.097

Modified: 2026-09-02T15:12:31.233

Link: CVE-2026-76658

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:43:49Z

Weaknesses