Description
A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to obtain elevated privileges and modify settings beyond what is authorized by the user's existing privilege level on a vulnerable system.
Published: 2026-09-01
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

A business logic flaw in the API of HPE Networking Fabric Composer grants an authenticated low‑privilege operator the ability to gain higher privileges and alter settings beyond their authorized level, effectively enabling privilege escalation. This weakness allows the attacker to perform actions normally restricted by role‑based controls, potentially exposing sensitive information and corrupting system configuration. The vulnerability aligns with CWE‑269 – Improper Privilege Management.

Affected Systems

The affected vendor is Hewlett Packard Enterprise, specifically the Fabric Composer product. No detailed version information was provided, so the full scope of impacted releases cannot be determined from the available data.

Risk and Exploitability

The CVSS score of 8.3 indicates a high severity vulnerability, but the EPSS score of 0.00287 (<1%) and the flaw is not listed in the CISA KEV catalog, suggesting limited known exploitation activity. Attackers would need authenticated access to the system, typically from an internal network or compromised administrator account. The real‑world impact therefore depends on the network segmentation and role configuration of the target environment.

Generated by OpenCVE AI on September 2, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE Networking Fabric Composer security update or patch that addresses the privilege escalation flaw
  • Configure network segmentation or firewall rules to restrict external and untrusted systems from contacting the vulnerable API endpoints
  • Enforce strict role‑based access controls, ensuring that low‑privilege users cannot invoke privileged operations, and regularly review permissions
  • Monitor audit logs for anomalous privilege escalation attempts and review configuration changes for unauthorized modifications

Generated by OpenCVE AI on September 2, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
Weaknesses CWE-863
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to obtain elevated privileges and modify settings beyond what is authorized by the user's existing privilege level on a vulnerable system.
Title Fault in Business Logic allows Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T15:25:18.439Z

Reserved: 2026-08-13T16:35:39.127Z

Link: CVE-2026-73708

cve-icon Vulnrichment

Updated: 2026-09-02T15:25:04.964Z

cve-icon NVD

Status : Modified

Published: 2026-09-01T20:17:18.190

Modified: 2026-09-02T16:17:20.493

Link: CVE-2026-73708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T21:38:55Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-863

    Incorrect Authorization