CVE-2026-73717: Unauthenticated Command Injection Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface
A command injection vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated remote attacker could exploit the web-based management interface. Exploitation requires certain preconditions that are outside the attacker’s control.
Does an attacker need valid credentials or user interaction?
No credentials are required, but the CVSS vector indicates user interaction is required. The advisory data does not specify what form that interaction takes.
What is the potential impact of successful exploitation?
Successful exploitation could let an attacker execute arbitrary commands on the underlying operating system, potentially resulting in complete system compromise.