CVE-2026-73704: Authenticated Command Injection Leading to Administrative Access in HPE Networking Fabric Composer API
Published Sep 1, 2026
·Updated
A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete compromise of the affected system.
Affected Software
1 affected component
HPE Networking Fabric Composer
Event History
Sep 1, 2026
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
DescriptionSeverity
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs an authenticated low-privilege operator account in HPE Networking Fabric Composer. No user interaction is required, and the attack can be performed over the network.
2
What is the likely impact after successful exploitation?
A successful attacker can escalate from the operator role to administrative privileges. This can lead to complete compromise of the affected Fabric Composer system.