
[CIVN-2026-0446] Multiple Vulnerabilities in HPE Aruba Networking Fabric Composer
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in HPE Aruba Networking Fabric Composer
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
HPE Networking Fabric Composer versions prior to 7.3.4
Overview
Multiple vulnerabilities have been reported in HPE Aruba Networking Fabric Composer which could be exploited by a remote attacker to bypass security restrictions, escalate privileges to administrative levels, execute arbitrary code on the underlying operating system, or cause denial-of-service (DoS) conditions on the target system.
Target Audience:
All organizations using HPE Aruba Networking Fabric Composer for network management.
Risk Assessment:
High risk of unauthorized administrative access, remote code execution (RCE), and complete system compromise.
Impact Assessment:
Potential for unauthenticated remote code execution, authentication bypass, privilege escalation, and denial-of-service (DoS).
Description
HPE Aruba Networking Fabric Composer is a centralized management solution used for configuring, monitoring, and managing network fabric infrastructures. It is designed to streamline network operations across various enterprise environments.
These vulnerabilities exist in HPE Aruba Networking Fabric Composer due to authentication bypasses in the API and underlying operating system; unauthenticated remote code execution in the SSH daemon and core OS; improper privilege assignment and broken access control within the API; and various command injection, SQL injection and cross-site scripting (XSS) flaws in the web-based management interface. A remote attacker could exploit these vulnerabilities by sending specially crafted requests to the management API, exploiting the SSH service, or through interactions with the web interface.
Successful exploitation of these vulnerabilities could allow a remote or adjacent attacker to bypass security restrictions, escalate privileges to administrative levels, execute arbitrary code on the underlying operating system, or cause denial-of-service (DoS) conditions on the target system, leading to complete system compromise.
Solution
Apply appropriate updates as mentioned by the vendor
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US
Vendor Information
HPE Networking
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US
References
HPE Networking
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US
CVE Name
CVE-2026-76657
CVE-2026-76658
CVE-2026-19766
CVE-2026-73700
CVE-2026-73701
CVE-2026-73702
CVE-2026-73703
CVE-2026-73704
CVE-2026-73705
CVE-2026-73706
CVE-2026-73707
CVE-2026-73708
CVE-2026-73709
CVE-2026-73710
CVE-2026-73711
CVE-2026-73712
CVE-2026-73713
CVE-2026-73714
CVE-2026-73715
CVE-2026-73716
CVE-2026-73717
CVE-2026-73718
CVE-2026-73719
CVE-2026-73720
CVE-2026-73721
CVE-2026-73722
CVE-2026-73723
CVE-2026-73724
CVE-2026-73725
CVE-2026-73726
CVE-2026-73727
CVE-2026-73728
CVE-2026-73729
CVE-2026-73730
CVE-2026-73731
CVE-2026-73732
CVE-2026-73733
CVE-2026-73734
CVE-2026-73735
CVE-2026-73736
CVE-2026-73737
CVE-2026-73738
CVE-2026-73739
CVE-2026-73740
CVE-2026-73741
CVE-2026-73742
CVE-2026-73743
CVE-2026-73744
CVE-2026-73745
CVE-2026-73746
CVE-2026-73747
CVE-2026-73748
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqiroIACgkQ3jCgcSdc
ys/unA/+Ke0frUItbx3nzKDH8tMXESb4Qho+8XoHF0WcncXoTpOXkhEePqKkxPj0
IR+aAdqFARj9+WK36R2w5J2UKZll9DPn9o7DjMlP0cgNUsZgA9eulCZ7KTXVkBXy
FinIHMlHZEK7Or5RUChJX5g82ZfYd1arb0Go3JsNvT2XbRUyGpmCMNbkgcjo8d5r
ZBrz/qHhuxLVH/oKH571zV/L/rzPrv2de7mhj5Jx9IhsMelmt7r8jhnAEzyxFxdN
yxkpIGulXkmJdKb/ok4HoRTPk7K9WQab8gyALH5ks8f6nQEqcIWFjkQVRRP5YsBG
4TYx0B2YpSR2sJ9GSLqtqnJiV6VAzjEJIe7aLH20bleF6T8u5+W3hWt91wiZ9h0A
IfZmRnGsMK4fmVj7Doco5tQrOYEuE7mcBUnFtp2jA398e8sbfT1ia6Fo9AZsmn7b
Ph/yQjlh+L65e3Q72SOviu3iK03jMRJJWd8U0mJ7Ym5rLgqpEM0BpL99nzuH50CB
r/n5NnvNtvffQor9DbeMTqM9LX50JaObQQPOS7hyvmskHPAK+OxcwEUWv3HAlF5N
DsrZvNz4UQLuWbQ9suU2tYcnlaeNE+Rg+XlOSlpqL+tz9/gHKMDfVJZ30sRSH8v5
2sIvlM+BQ3+/RbrNGyTIs5wPRSbpo3sQX0nACuvcCB6u425GbT8=
=MkGs
—–END PGP SIGNATURE—–


