A remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system, leading to complete compromise of the HPE Networking Fabric Composer host.
References
| Link | Resource |
|---|---|
| https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-09-01 20:17
Updated : 2026-09-02 19:18
NVD link : CVE-2026-73716
Mitre link : CVE-2026-73716
CVE.ORG link : CVE-2026-73716
JSON object : View
Products Affected
arubanetworks
- fabric_composer
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
