Critical HPE Fabric Composer Flaw Lets Unauthenticated Attackers Execute Commands as Root
Brief
HPE Networking has released security updates for Fabric Composer following the disclosure of a broad set of vulnerabilities, including two maximum-severity flaws that could allow unauthenticated remote attackers to take administrative control of affected systems.
The most severe issue, tracked as CVE-2026-76658, affects the product’s SSH daemon and can enable arbitrary command execution as a privileged operating system user, potentially resulting in a complete compromise of the Fabric Composer host.
The advisory HPESBNW05133 covers HPE Networking Fabric Composer versions 7.
- 3 and earlier.
Critical HPE Fabric Composer Flaw
HPE assigns CVSS v3. 1 scores of 10. 0 to both CVE-2026-76658 and CVE-2026-76657, reflecting network-reachable attack paths, low attack complexity, no authentication requirement, and high impact to confidentiality, integrity, and availability.
