CVE-2026-19766 PUBLISHED

Authentication Bypass leads to Administrative control of adjacent network hosts in HPE Networking Fabric Composer

Assigner: hpe
Reserved: 13.08.2026 Published: 01.09.2026 Updated: 02.09.2026

An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.6

Product Status

Vendor Hewlett Packard Enterprise (HPE)
Product Fabric Composer
Versions Default: affected
  • affected from 7.0.0 to 7.3.3 (incl.)

Credits

  • This vulnerability was discovered by internal security research at HPE Networking. reporter

References