CVE-2026-76657

10.0

Hewlett Packard Enterprise (HPE) · Fabric Composer

An authentication bypass vulnerability in the HPE Fabric Composer API allows unauthenticated remote attackers to gain administrative privileges and fully compromise the host.

Executive summary

A critical authentication bypass vulnerability in HPE Fabric Composer enables unauthenticated remote attackers to achieve full administrative control over the affected host.

Vulnerability

The flaw resides within the API implementation, allowing an unauthenticated remote attacker to circumvent authentication controls. By exploiting this vulnerability, an attacker can elevate their access to administrative status without requiring valid credentials.

Business impact

The potential for a complete system compromise represents a severe threat to organizational security and data integrity. Given the CVSS score of 10.0, this vulnerability allows for total loss of confidentiality, integrity, and availability of the Fabric Composer host. Such access could facilitate lateral movement within the network, unauthorized data exfiltration, or the deployment of malicious payloads throughout the infrastructure.

Remediation

Immediate Action: Update HPE Fabric Composer to the latest patched version as specified in the official vendor advisory.

Proactive Monitoring: Review system access logs for anomalous API requests or unauthorized administrative login attempts originating from unknown IP addresses.

Compensating Controls: Implement strict network segmentation and restrict access to the Fabric Composer API interface to trusted management networks using a Web Application Firewall or host-based firewall rules.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability is classified as critical due to its potential for unauthenticated remote code execution and full system takeover. Organizations currently running versions 7.0.0 through 7.3.3 of HPE Fabric Composer must prioritize applying the vendor provided updates immediately to prevent unauthorized access. Failure to patch these systems leaves the management layer of the network fabric exposed to remote attackers.

More Hewlett Packard Enterprise (HPE) CVEs

Sources

Originally found and disclosed by This vulnerability was discovered by internal security research at HPE Networking., per the CVE Program record.