Description
Vulnerabilities in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to make limited unauthorized modifications to the underlying operating system and disrupt the availability of the affected system, requiring manual intervention to restore functionality.
Published: 2026-09-01
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A remote attacker can exploit an unsecured API endpoint in HPE Networking Fabric Composer to trigger a denial of service. The vulnerability allows the attacker to send unauthenticated requests that consume resources and cause the system to become unavailable. In addition to disrupting availability, exploitation may enable the attacker to perform limited unauthorized modifications on the underlying operating system, potentially compromising system integrity. The impact therefore spans both availability and a risk of unauthorized control changes.

Affected Systems

Hewlett Packard Enterprise’s Fabric Composer product is affected. No specific firmware or software version ranges are enumerated in the notes, indicating that all versions of Fabric Composer that include the vulnerable API endpoint may be impacted.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity level, while the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely remote and unauthenticated, requiring only the ability to reach the affected API endpoint. Successful exploitation does not require local access or privileged credentials, but it can lead to service disruption and potentially unauthorized system modifications, posing a significant risk to operational continuity.

Generated by OpenCVE AI on September 3, 2026 at 15:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE Fabric Composer patch or update that eliminates the unauthenticated API endpoint vulnerability.
  • Restrict network access to the Fabric Composer API by configuring firewall rules or segmenting the management network so that only trusted hosts can communicate with the endpoint.
  • Enable continuous monitoring of system availability and API request rates, and configure alerts for sudden spikes or service failures that may indicate a denial‑of‑service attack.

Generated by OpenCVE AI on September 3, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-770

Wed, 02 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-770

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerabilities in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to make limited unauthorized modifications to the underlying operating system and disrupt the availability of the affected system, requiring manual intervention to restore functionality.
Title Unauthenticated Denial of Service Vulnerabilities in API Endpoint of HPE Networking Fabric Composer
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T14:40:01.341Z

Reserved: 2026-08-13T16:36:38.745Z

Link: CVE-2026-73710

cve-icon Vulnrichment

Updated: 2026-09-02T14:39:54.308Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:18.400

Modified: 2026-09-02T16:24:04.913

Link: CVE-2026-73710

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:30:05Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function