Sceawere

Vulnerability Detail

CVE-2026-76658UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

HPE AFC SSH Authentication Bypass

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
2h ago
Vendor
Hewlett Packard Enterprise (HPE)
Product
Fabric Composer
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-09-01T20:17:23.097Z",
  "pubdate": "2026-09-01T20:17:23.097Z",
  "executiveSummary": "A critical vulnerability exists within the SSH daemon implementation of HPE Networking Fabric Composer (AFC) that permits unauthenticated remote attackers to circumvent standard authentication mechanisms.\nThis flaw allows for unauthorized access to the underlying operating system with administrative privileges, facilitating complete system compromise.\nThe vulnerability is classified as an authentication bypass or improper access control within the SSH subsystem.\nBecause the vulnerability is exploitable remotely without requiring prior authentication, it poses a severe risk to network infrastructure integrity.\nSuccessful exploitation grants an attacker the ability to execute arbitrary commands at the root or superuser level, effectively bypassing all security boundaries configured within the HPE Networking Fabric Composer environment.\nImpact includes total loss of confidentiality, integrity, and availability of the affected AFC host, potentially enabling lateral movement across the fabric management plane.",
  "technicalDetails": "The vulnerability resides in the SSH daemon (sshd) component bundled within the HPE Networking Fabric Composer operating environment. Investigations indicate that the root cause involves an flaw in the authentication logic, which fails to correctly validate or enforce credentials for incoming SSH connection requests.\nThe attack flow initiates when an unauthorized remote actor establishes a TCP connection to the SSH service port (typically 22/tcp) on the target AFC host. Instead of adhering to the standard SSH protocol handshake requirements that necessitate valid key-based or password-based authentication, the vulnerable daemon erroneously processes specific malformed or crafted authentication requests as valid.\nThe exploitation mechanism allows an attacker to bypass the cryptographic verification and session management routines of the SSH daemon. By failing to perform a complete authentication check, the daemon prematurely transitions the connection state to an authenticated session, granting the client an active shell environment.\nOnce the authentication boundary is bypassed, the attacker is granted an interactive session with the privileges of the service owner, which in the context of the HPE Networking Fabric Composer sshd, results in elevated administrative or root access to the underlying Linux-based operating system.\nPayload execution at this stage is unrestricted; an attacker can invoke system binaries, modify configuration files, exfiltrate sensitive data, or install persistent backdoors. The post-exploitation impact includes the potential for command-and-control (C2) deployment, direct manipulation of network fabric configuration, and complete neutralization of existing security telemetry.\nThe vulnerability is remotely exploitable, requiring only network reachability to the management interface of the AFC host. There are no prerequisite user interactions or specific account credentials required to initiate the attack chain. The failure occurs within the server-side validation process, meaning the vulnerability persists regardless of the security strength of the local user accounts."
}
CVE-2026-76658: HPE AFC SSH Authentication Bypass (CRITICAL Severity, CVSS: 10.0) - Sceawere