HPE Fabric Composer の脆弱性 CVE-2026-76658 などが FIX:基盤となるホストの完全侵害の恐れ

Critical HPE Fabric Composer Flaw Lets Unauthenticated Attackers Execute Commands as Privileged User

2026/09/01 gbhackers — Hewlett Packard Enterprise (HPE) が公表したのは、HPE Networking Fabric Composer に存在する 52 件の脆弱性と、それらに対するセキュリティ・アップデートである。このうち 5 件は重大な脆弱性で、未認証のリモート攻撃者による管理者権限の取得/特権 OS ユーザーとしてのコマンド実行につながる可能性がある。これらの脆弱性が影響を及ぼすのは、Fabric Composer バージョン 7.3.3 以下である。

HPE Fabric Composer の脆弱性

1 件目の深刻な脆弱性 CVE-2026-76658 (CVSS:10.0) は、同製品の SSH デーモンに存在する認証の欠陥に起因する。この脆弱性を悪用する攻撃者は、脆弱な AFC ホストへのアクセスにおいて、認証情報/ユーザー操作/複雑な準備を必要としない。悪用に成功した攻撃者は、特権コマンドを任意に実行し、基盤となるホストを完全に侵害する可能性がある。

2 件目の脆弱性 CVE-2026-76657 (CVSS:10.0) は、Fabric Composer API に影響を及ぼす。この脆弱性を悪用する未認証のリモート攻撃者は、認証制御を回避して管理者権限を取得し、システムを完全に掌握できる。いずれの脆弱性もネットワーク経由で悪用でき、攻撃の複雑性も低いため、機密性/完全性/可用性に重大なリスクをもたらす。

さらに、別の 3 件の脆弱性も重大と評価されている。CVE-2026-19766 を悪用する隣接ネットワーク上の未認証の攻撃者は、認証を回避して特権コードを実行できる。また、CVE-2026-73700 は保存型クロスサイト・スクリプティング (XSS) の脆弱性であり、低権限のオペレータが管理者を標的にする可能性がある。CVE-2026-73701 では、特定の前提条件が満たされた場合、未認証のユーザーがリモートから特権コードを実行できる。

残りのアドバイザリが対象とするのは、高深刻度 24 件/中深刻度 17 件/低深刻度 6 件の脆弱性である。そこに含まれるのは、コマンド実行/SQL インジェクション/任意のファイル書き込み/アクセス制御の不備/機密データの漏洩/サービス拒否 (DoS)/パストラバーサル/オープンリダイレクト/リクエストの帰属情報の偽装/ローカル権限昇格などである。

これらの脆弱性の多くは、root 権限でのコード実行/Fabric Composer が管理するシステムへの未認可の変更につながる可能性があることから、外部に公開された管理インターフェイスは攻撃者にとって魅力的な標的となる。

HPE によると、これらの脆弱性はすべて同社のネットワーク・セキュリティ研究者が発見したものであり、9月1日にアドバイザリが公開された時点で、これらの脆弱性を標的とする公開された議論/悪用コードは確認されていない。現時点で実環境における悪用を示す証拠は確認されていないが、多様な攻撃経路が存在し、未認証で侵害される可能性もあるため、修正の緊急性が低下するわけではない。

管理者に推奨される対応は、Fabric Composer 7.3 ブランチのバージョン 7.3.4 以降へのアップグレード、もしくはバージョン 7.4.0 以降への移行である。保守終了となったリリースも影響を受けると推定されるが、影響について評価されていないため、脆弱な可能性があるものとして扱う必要がある。

パッチ適用が完了するまでの間において HPE が推奨するのは、CLI/Web 管理用インターフェイスを専用のレイヤー 2 セグメントまたは VLAN に配置し、レイヤー 3 ファイアウォール・ポリシーでアクセスを制限することだ。また、管理者は、異常な SSH/API/管理者の活動がないかログを確認し、侵害が疑われる場合には外部に公開された認証情報を更新する必要がある。

CVE Details
CVEVulnerabilitySeverityCVSS
CVE-2026-76657API authentication bypass grants administrative accessCritical10.0
CVE-2026-76658Unauthenticated RCE in SSH daemonCritical10.0
CVE-2026-19766Adjacent-network authentication bypass and privileged code executionCritical9.6
CVE-2026-73700Authenticated stored XSS in management interfaceCritical9.0
CVE-2026-73701Unauthenticated privileged RCE with preconditionsCritical9.0
CVE-2026-73702Authenticated API privilege escalationHigh8.8
CVE-2026-73703Adjacent-network stored XSSHigh8.8
CVE-2026-73704Authenticated API command injectionHigh8.8
CVE-2026-73705Arbitrary file write leading to RCEHigh8.8
CVE-2026-73706API authentication bypass, data exposure and unauthorized changesHigh8.6
CVE-2026-73707API broken access control and privilege escalationHigh8.5
CVE-2026-73708Business-logic flaw exposing sensitive informationHigh8.3
CVE-2026-73709Adjacent-network RCE during installationHigh8.3
CVE-2026-73710Unauthenticated API denial of serviceHigh8.2
CVE-2026-73711Improper privilege assignment grants administrative accessHigh8.1
CVE-2026-73712Unauthenticated API remote code executionHigh8.1
CVE-2026-73713Local privilege escalation to rootHigh7.8
CVE-2026-73714Authenticated API information disclosureHigh7.6
CVE-2026-73715Unauthenticated API denial of serviceHigh7.5
CVE-2026-73716Unauthenticated privileged RCE requiring interaction/preconditionsHigh7.5
CVE-2026-73717Unauthenticated management-interface command injectionHigh7.5
CVE-2026-73718Web-interface sensitive information disclosureHigh7.4
CVE-2026-73719Administrative arbitrary file write leading to root RCEHigh7.2
CVE-2026-73720Insecure API file handling leading to RCEHigh7.2
CVE-2026-73721Authenticated API SQL injectionHigh7.2
CVE-2026-73722Authenticated management-interface command injectionHigh7.2
CVE-2026-73723Privilege escalation enabling unauthorized state changesHigh7.1
CVE-2026-73724Broken access control enabling settings changesHigh7.1
CVE-2026-73725Local privilege escalation and root code executionHigh7.0
CVE-2026-73726Adjacent-network authentication bypassMedium6.8
CVE-2026-73727Authenticated API information disclosureMedium6.5
CVE-2026-73728Authenticated API denial of serviceMedium6.5
CVE-2026-73729Local authenticated information disclosureMedium6.5
CVE-2026-73730Authenticated API privilege escalationMedium6.5
CVE-2026-73731Unauthenticated reflected XSSMedium6.1
CVE-2026-73732Local sensitive information disclosureMedium5.6
CVE-2026-73733API authentication bypass allowing continued accessMedium5.4
CVE-2026-73734Unauthenticated open redirectMedium5.4
CVE-2026-73735API access-control flaws exposing informationMedium5.4
CVE-2026-73736Unauthenticated limited information disclosureMedium5.3
CVE-2026-73737Adjacent-network API path traversal and file modificationMedium4.8
CVE-2026-73738Local authenticated information disclosureMedium4.7
CVE-2026-73739Local authenticated API information disclosureMedium4.4
CVE-2026-73740Local privilege escalationMedium4.4
CVE-2026-73741Authenticated API limited file readMedium4.3
CVE-2026-73742Client-address validation flaw enables attribution spoofingMedium4.3
CVE-2026-73743Unauthenticated information disclosureLow3.7
CVE-2026-73744Authenticated management-interface denial of serviceLow3.5
CVE-2026-73745Unauthenticated limited API information disclosureLow3.1
CVE-2026-73746Authenticated API denial of serviceLow3.1
CVE-2026-73747Local privilege escalationLow2.5
CVE-2026-73748Authenticated information disclosureLow2.2