CVE-2026-73709: Unauthenticated Remote Code Execution during HPE Networking Fabric Composer Installation Process
Published Sep 1, 2026
·Updated
A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
Affected Software
1 affected component
HPE Networking Fabric Composer
Event History
Sep 1, 2026
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of network access would an attacker need?
The attacker must be adjacent to the affected HPE Networking Fabric Composer host. The issue is not described as exploitable by an attacker without that adjacent network position.
2
Are credentials or user interaction required for exploitation?
No privileges or user interaction are required. However, exploitation depends on certain preconditions that are outside the attacker’s control.