Home

Description

Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could allow authenticated attackers to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

PUBLISHED Reserved 2026-01-14 | Published 2026-01-27 | Updated 2026-01-27 | Assigner hpe




HIGH: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Product status

Default status
affected

7.0.0 (semver)
affected

Credits

Daniel Jensen (@dozernz) reporter

References

support.hpe.com/...y?docId=hpesbnw04996en_us&docLocale=en_US

cve.org (CVE-2026-23592)

nvd.nist.gov (CVE-2026-23592)

Download JSON