Command Injection Vulnerability in HPE Networking Fabric Composer
CVE-2026-73717

7.5HIGH

Key Information:

Vendor

HP (HP)

Vendor
CVE Published:
1 September 2026

What is CVE-2026-73717?

A command injection vulnerability in the web-based management interface of HPE Networking Fabric Composer allows unauthenticated remote attackers to execute arbitrary commands on the underlying host. This exploitation requires specific preconditions that are out of the attacker's control. Should these conditions be met, an attacker could perform malicious actions leading to unauthorized access and potentially full system compromise, putting sensitive data and operations at risk.

Affected Version(s)

Fabric Composer 7.0.0 <= 7.3.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Unknown contributor
.