News

Fabric Composer SSH grants unauthenticated admin access

Louis Stowasser
Louis Stowasser
Saturday 5 September 2026
Fabric Composer SSH grants unauthenticated admin access
Fabric Composer SSH grants unauthenticated admin access

HPE Aruba Networking Fabric Composer is the control plane used to provision and operate CX data-centre switching fabrics. Network and infrastructure teams use it to push switch configuration, build leaf-spine and EVPN fabrics, manage routing and segmentation, and connect network operations with platforms such as virtualisation and private-cloud tooling. That puts it in enterprise and service-provider data centres, private-cloud estates, and other environments where a small team centrally manages substantial compute, storage and network infrastructure.

CVE-2026-76658 is a flaw in the SSH daemon running on the Fabric Composer host, not a separately purchased SSH product. HPE says an unauthenticated remote attacker can gain administrative access to an affected host, then execute arbitrary commands as a privileged operating-system user. In practical terms, someone who can reach the exposed service may not need a Fabric Composer account, a password, or an existing foothold before taking control of the appliance or VM that manages part of the fabric.

The authentication boundary fails before login

The advisory classifies the issue as improper authentication: the SSH service does not reliably enforce the check that should separate an unauthenticated network connection from administrative host access. The implementation detail matters here because it is not public: no vendor patch diff, vulnerable code, affected function, or exact bypass sequence has been published. HPE describes the resulting account only as “a privileged user”; claims that this necessarily means root cannot be confirmed.

The scope is unusually consequential because Fabric Composer is an orchestration system. Command execution on its underlying operating system can expose stored configuration and credentials and may give an intruder a position from which to alter the management plane or reach connected network infrastructure. Those follow-on outcomes depend on each deployment’s integrations and permissions, but the initial compromise requires only network reachability to the vulnerable SSH daemon.

HPE’s September 1 bulletin rates CVE-2026-76658 at CVSS 10.0 and includes it among a broader Fabric Composer release, including the API issue CVE-2026-76657. HPE says its internal Networking security researchers found the SSH flaw.

Upgrade, then shrink the management path

Fabric Composer 7.0.0 through 7.3.3 are affected. HPE provides corrected releases: upgrade the 7.3 line to 7.3.4 or later, or move to 7.4.0 or later on that branch. The vendor’s compatibility material identifies builds 15979 for 7.3.4 and 15980 for 7.4.0. End-of-maintenance releases are presumed affected unless explicitly excluded; end-of-support branches were not assessed, so teams should treat them as potentially exposed rather than assuming they are safe.

Until upgrades are complete, restrict both CLI and web management interfaces to a dedicated Layer 2 segment or VLAN, or enforce Layer 3 firewall policies. Inventory every Fabric Composer instance, verify its actual release and build, remove broad SSH reachability, and review who can reach the management network. This is also a good moment to check integrations and rotate credentials if there is any indication that an instance was exposed beyond its intended administrators.

No public exploitation evidence so far

As of September 5, 2026, exploitation in the wild could not be confirmed. HPE reported no public discussion or exploit code for the bulletin’s flaws at disclosure, and no public proof of concept surfaced in subsequent searches; that does not rule out private tooling. CVE-2026-76658 was also not listed in CISA’s Known Exploited Vulnerabilities catalogue at that time, and no public campaign, actor attribution, incident report, or vendor indicators of compromise have been connected to it.

The immediate job is straightforward: patch the control plane and make SSH management reachable only from where it must be. SecAlerts monitors an organisation’s actual software stack and alerts on new vulnerabilities affecting the products it runs, which helps keep this kind of infrastructure exposure from becoming an inventory surprise.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203