Description
Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform, including changes to the configuration of systems managed by the affected product.
Published: 2026-09-01
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an access‑control failure (CWE‑863) in the HPE Fabric Composer API that lets an authenticated low‑privileged operator perform state‑changing actions such as modifying configuration settings. Because the platform does not enforce proper authorization checks, the attacker can elevate privileges and alter system behavior, potentially compromising the integrity of the network fabric and disrupting available services.

Affected Systems

All versions of Hewlett Packard Enterprise’s Fabric Composer API are potentially affected, as the advisory does not disclose a specific affected version range. Until a vendor‑supplied fix is applied, any machine running the product and accessible to a low‑privilege account is at risk. The flaw applies to the API endpoints that perform configuration changes, so any deployment of Fabric Composer that exposes those endpoints is vulnerable.

Risk and Exploitability

The CVSS base score of 8.5 places this flaw in the ‘high’ severity range, but the EPSS score is listed as less than 1 %, indicating a very low current probability of exploitation in the wild. The vulnerability is not yet catalogued in CISA’s KEV list. Successful exploitation requires that the attacker possess a low‑privilege authenticated session and discover the state‑changing API endpoints; if achieved, the attacker can gain unauthorized configuration authority, which may lead to network outages or data integrity problems.

Generated by OpenCVE AI on September 3, 2026 at 13:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or update recommended in the HPE advisory as soon as it becomes available.
  • Configure role‑based access controls so that only privileged users have permissions to invoke state‑changing API endpoints.
  • Restrict or disable any unused API endpoints that can alter configuration, and ensure that only management devices within a trusted network segment can reach the API.
  • Implement network segmentation or firewall policies that limit exposure of the Fabric Composer API to authorized management hosts.

Generated by OpenCVE AI on September 3, 2026 at 13:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 02 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
Weaknesses CWE-863
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform, including changes to the configuration of systems managed by the affected product.
Title Authenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric Composer API
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T15:22:16.425Z

Reserved: 2026-08-13T16:35:39.127Z

Link: CVE-2026-73707

cve-icon Vulnrichment

Updated: 2026-09-02T15:22:13.960Z

cve-icon NVD

Status : Modified

Published: 2026-09-01T20:17:18.087

Modified: 2026-09-02T16:17:20.377

Link: CVE-2026-73707

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T13:45:04Z

Weaknesses