T

Threats

HPE Networking Fabric Composer Critical Vulnerabilities

Overview

CVE: CVE-2026-76657, CVE-2026-76658, CVE-2026-19766, CVE-2026-73700, CVE-2026-73701

Severity: Critical

Date: 1 September 2026

HPE has released security updates for HPE Networking Fabric Composer to address five critical vulnerabilities. Depending on the flaw, successful exploitation could allow an unauthenticated attacker to bypass authentication, obtain administrative access, or execute privileged code or commands. One vulnerability requires adjacent network access, while another requires a low-privilege operator account and interaction by an administrative user.


Affected Versions

HPE Networking Fabric Composer 7.3.x

HPE Networking Fabric Composer 7.4.x


Vulnerability Breakdown

CVE-2026-76657 - API Authentication Bypass

  • Severity: Critical

  • CVSS: 10.0

  • Description: Vulnerabilities in the Fabric Composer API could allow an unauthenticated remote attacker to circumvent existing authentication controls.

  • Impact: Administrative privileges and complete compromise of the Fabric Composer host.

  • Conditions: Remote network access. No authentication is required.

CVE-2026-76658 - SSH Daemon Authentication Bypass

  • Severity: Critical

  • CVSS: 10.0

  • Description: A vulnerability in the Fabric Composer SSH daemon could allow an unauthenticated remote attacker to gain administrative access to a vulnerable host.

  • Impact: Arbitrary command execution as a privileged user, leading to complete system compromise.

  • Conditions: Remote network access. No authentication is required.

CVE-2026-19766 - Operating System Authentication Bypass

  • Severity: Critical

  • CVSS: 9.6

  • Description: An authentication bypass vulnerability in the underlying operating system could allow an unauthenticated adjacent attacker to execute arbitrary code.

  • Impact: Privileged code execution and complete compromise of the Fabric Composer host.

  • Conditions: The attacker must have adjacent network access. No authentication is required.

CVE-2026-73700 - Stored Cross-Site Scripting

  • Severity: Critical

  • CVSS: 9.0

  • Description: A flaw in the web-based management interface could allow an authenticated low-privilege operator to store malicious script content that executes in an administrative user's browser.

  • Impact: Arbitrary script execution in the context of the affected management interface.

  • Conditions: A low-privilege operator account and interaction by an administrative user are required.

CVE-2026-73701 - Remote Code Execution

  • Severity: Critical

  • CVSS: 9.0

  • Description: A vulnerability in the underlying operating system could allow unauthenticated remote code execution when certain preconditions outside the attacker's control are met.

  • Impact: Arbitrary code execution as a privileged user and complete compromise of the Fabric Composer host.

  • Conditions: No authentication is required, but specific environmental preconditions must be met.


Mitigation

  • Upgrade HPE Networking Fabric Composer 7.3.x deployments to version 7.3.4 or later.

  • Alternatively, upgrade to HPE Networking Fabric Composer 7.4.0 or later.

  • Prioritise internet-facing or broadly accessible management deployments because multiple flaws require no authentication.

  • Confirm the installed version after remediation and monitor administrative and SSH access for suspicious activity.


Summary for IT Teams

  • Products: HPE Networking Fabric Composer

  • Threat Level: Critical, CVSS up to 10.0

  • Action Required: Upgrade affected Fabric Composer deployments to 7.3.4 or later, or to 7.4.0 or later, as soon as possible.


Reference


Need Help?

Secure ISS can help your organisation assess exposure, plan remediation, and validate HPE Networking Fabric Composer updates. Contact the Secure ISS SOC team on 1300 769 460.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.