Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-76657: HPE Fabric Composer API lets remote attacker gain admin access

CVE-2026-76657 · published 2 days ago
Summary

The web interface that manages HPE Networking Fabric Composer can be tricked into granting full control without a valid login. An attacker could then take over the management server and change or disrupt network settings. Apply the vendor's security update or restrict access to trusted users immediately.

What to do
  • Update arubanetworks fabric_composer to version 7.3.4 or later.
Affected software
VendorProductAffected versions
hewlett packard enterprise (hpe) fabric composer <= 7.3.3
arubanetworks fabric_composer < 7.3.4
cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Original advisory text
Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Suc...
Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.
Severity
10.0 Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published1 Sep 2026
Updated2 Sep 2026
First seen1 Sep 2026
Sources
CVE-2026-76657 · MITRE
Monitor software like this
Free during beta