← Terug naar overzicht

CVE-2026-19766 is an authentication bypass vulnerability in the underlying operating system of HPE Networking Fabric Composer (AFC). An unauthenticated attacker with adjacent network access can exploit this flaw to execute arbitrary code as a privileged user on the underlying OS. Successful exploitation leads to complete compromise of the AFC host. No authentication is required, lowering the bar for exploitation significantly. The vulnerability is currently awaiting full analysis by NVD. HPE has published a security bulletin with further details and remediation guidance. The severity is rated High due to the potential for full system takeover. Organizations using HPE Networking Fabric Composer should review the HPE advisory immediately and apply any available patches or mitigations.

Affected products

  • HPE Networking Fabric Composer

Related CVE's

  • CVE-2026-19766

Categories

  • Identity & Access
  • Network Infrastructure
  • Zero-Day Vulnerabilities