CVE-2026-73722: Authenticated Command Injection Vulnerabilities in HPE Networking Fabric Composer Web-Based Management Interface
Published Sep 1, 2026
·Updated
Command injection vulnerabilities in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated remote attacker to perform command injection against the affected system. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Affected Software
1 affected component
HPE HPE Networking Fabric Composer
Event History
Sep 1, 2026
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
DescriptionSeverity
Frequently Asked Questions
1
Does exploitation require a highly privileged existing account?
Yes. The CVSS vector assigns Privileges Required as High, so an attacker must already have high-level authenticated access to the web-based management interface.
2
Is user interaction needed once an attacker has the required access?
No. The CVSS vector specifies User Interaction as None and Attack Complexity as Low.