CVE-2026-73720

Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-01 20:17

Updated : 2026-09-02 16:17


NVD link : CVE-2026-73720

Mitre link : CVE-2026-73720

CVE.ORG link : CVE-2026-73720


JSON object : View

Products Affected

arubanetworks

  • fabric_composer
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-73

External Control of File Name or Path