CVE-2026-73705
Awaiting Analysis Awaiting Analysis - Queue

HPE Networking Fabric Composer Arbitrary File Write Vulnerability

Vulnerability report for CVE-2026-73705, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Hewlett Packard Enterprise (HPE)

Description

An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary commands on the underlying operating system, leading to complete compromise of the affected system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hpe networking_fabric_composer *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an arbitrary file write vulnerability in HPE Networking Fabric Composer's API. It allows an authenticated low privilege operator user to escalate privileges. Exploitation could let attackers execute arbitrary commands on the system, potentially leading to full system compromise.

Impact Analysis

If exploited, this vulnerability could allow attackers to gain complete control over the affected system. This means they could install malware, steal data, disrupt operations, or use the system for further attacks within your network.

Compliance Impact

This vulnerability allows an authenticated low privilege operator to escalate privileges and execute arbitrary commands on the underlying operating system. Such unauthorized access could lead to data breaches, unauthorized data exposure, or manipulation, which directly impacts compliance with GDPR and HIPAA by violating data integrity, confidentiality, and availability requirements.

Mitigation Strategies

Apply patches or updates provided by HPE for Networking Fabric Composer to address the arbitrary file write vulnerability. Ensure only authorized users have access to the API and monitor for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73705. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart