CVE-2026-73720: Authenticated Insecure File Handling allows Remote Code Execution in HPE Networking Fabric Composer API
Published Sep 1, 2026
·Updated
Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Affected Software
1 affected component
HPE Networking Fabric Composer API
Event History
Sep 1, 2026
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker must be authenticated to the HPE Networking Fabric Composer API. The attack can be performed remotely and does not require user interaction.
2
What is the potential impact after successful exploitation?
Successful exploitation can allow execution of arbitrary commands as a privileged user on the underlying operating system. This can affect confidentiality, integrity, and availability.