CVE-2026-76658

10.0

Hewlett Packard Enterprise (HPE) · Fabric Composer

A critical vulnerability in the HPE Fabric Composer SSH daemon allows unauthenticated remote attackers to achieve full administrative system compromise via arbitrary command execution.

Executive summary

An unauthenticated remote code execution vulnerability in HPE Fabric Composer enables full system compromise, representing a critical security risk.

Vulnerability

The vulnerability exists within the SSH daemon of the Fabric Composer software. It allows an unauthenticated remote attacker to bypass authentication mechanisms and execute arbitrary commands with root-level privileges on the underlying operating system.

Business impact

The potential impact of this vulnerability is total system compromise, allowing an attacker to gain full control over the network infrastructure managed by Fabric Composer. Given the CVSS score of 10.0, this flaw poses an extreme risk to confidentiality, integrity, and availability, likely resulting in unauthorized data access, network disruption, and potential lateral movement within the enterprise environment.

Remediation

Immediate Action: Update Hewlett Packard Enterprise (HPE) Fabric Composer to the latest patched version available in the official vendor security advisory.

Proactive Monitoring: Review system access logs for any unauthorized SSH authentication attempts or anomalous command execution patterns occurring from unknown or untrusted source IP addresses.

Compensating Controls: Restrict network access to the Fabric Composer management interface to known, trusted management segments using access control lists or firewall rules to prevent external exposure.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the critical severity and the potential for total system takeover, organizations using the affected versions of HPE Fabric Composer must prioritize this update. Immediate patching is required to eliminate the risk of remote command execution, and network isolation should be maintained until the remediation is successfully deployed and verified.

More Hewlett Packard Enterprise (HPE) CVEs

Sources

Originally found and disclosed by This vulnerability was discovered by internal security research at HPE Networking., per the CVE Program record.