HPE has released security updates for HPE Networking Fabric Composer following the discovery of a large set of vulnerabilities that could allow unauthenticated attackers to gain administrator access, run arbitrary commands, and fully compromise affected systems.

The flaws affect HPE Networking Fabric Composer version 7.3.3 and earlier. Fabric Composer is used to manage and automate data-center network fabrics, making a successful compromise particularly serious because the platform can control important network infrastructure.

The most severe vulnerabilities are tracked as CVE-2026-76657 and CVE-2026-76658. Both received a maximum CVSS score of 10.0.

HPE said the API authentication-bypass flaw, CVE-2026-76657, could allow a remote attacker to circumvent existing authentication controls and obtain administrative privileges without valid credentials. This access could lead to a complete takeover of the Fabric Composer host.

CVE-2026-76658 affects the product’s SSH daemon. An unauthenticated remote attacker could exploit the issue to gain administrative access and execute arbitrary commands as a privileged user on the underlying operating system.

HPE Fabric Composer Flaws

In practical terms, a successful exploit may give an attacker control of the appliance and the ability to alter its configuration, steal information, or use it as a foothold for further movement inside an organization’s network.

HPE also fixed CVE-2026-19766, an adjacent-network authentication bypass rated 9.6. The vulnerability could allow an unauthenticated attacker on a connected network segment to execute arbitrary code with privileged operating-system permissions.

Other serious findings include unauthenticated remote code execution bugs, stored cross-site scripting issues, command injection, arbitrary file write, SQL injection, privilege escalation, information disclosure, and denial-of-service flaws.

Several weaknesses are especially concerning because they can be chained. For example, an attacker may first use an information-disclosure bug to understand internal services, then exploit an authentication bypass or remote code execution flaw to take control of the server.

Lower-privileged Fabric Composer users may also be able to exploit API and web interface flaws to escalate to administrative access.

HPE said its internal security researchers discovered the vulnerabilities. At the time the advisory was released, the company said it was not aware of public exploit code or public discussion targeting the issues.

However, the broad range and high severity of the bugs make prompt patching important, particularly for systems whose management interfaces are reachable from untrusted networks.

Organizations using Fabric Composer should upgrade to version 7.4.0 or later in the 7.4 branch, or version 7.3.4 or later in the 7.3 branch.

HPE also recommends restricting command-line and web-based management interfaces to a dedicated Layer 2 segment or VLAN, enforcing Layer 3 firewall controls, and using logging and accounting controls to track access and user activity.

Older releases that have reached End of Maintenance should be treated as potentially exposed unless HPE has explicitly stated otherwise.

Administrators should identify all Fabric Composer installations, confirm their running versions, apply the vendor’s fixes, and review administrator accounts, SSH exposure, API access, and network management logs for suspicious activity.