Description
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to access sensitive information if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.
Published: 2026-09-01
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The affected product is the HPE Networking Fabric Composer web interface. The vulnerability allows an unauthenticated remote attacker to trick an authenticated user into visiting a crafted URL, leading to retrieval of sensitive configuration or system data. The disclosure can provide information that might help the attacker expand their foothold into other network services. This weakness corresponds to a cross‑site request forgery flaw (CWE‑352).

Affected Systems

Hewlett Packard Enterprise (HPE): Fabric Composer. The specific affected versions are not listed, so all currently deployed versions are considered vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 7.4 indicates a high severity, and the EPSS score of < 1% indicates a very low exploitation probability. The CVE is not listed in the CISA KEV catalog. Because the attack requires the attacker to persuade an authenticated user to click a crafted URL, the risk is primarily social‑engineering based. Once the user interacts, the attacker can read sensitive data that may be used to move laterally within the network.

Generated by OpenCVE AI on September 3, 2026 at 15:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE patch or upgrade Fabric Composer to a version that eliminates the web‑interface information‑exposure flaw.
  • Limit the web interface to trusted IP ranges or VLANs, and enforce strict firewall rules to restrict unauthenticated access.
  • Enforce multi‑factor authentication for all Fabric Composer users to reduce the success rate of social‑engineering attempts.

Generated by OpenCVE AI on September 3, 2026 at 15:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Wed, 02 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to access sensitive information if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.
Title Unauthenticated Information Disclosure in Web Interface allows Sensitive Data Exposure in HPE Networking Fabric Composer
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T15:26:07.234Z

Reserved: 2026-08-13T16:36:38.746Z

Link: CVE-2026-73718

cve-icon Vulnrichment

Updated: 2026-09-02T15:26:04.320Z

cve-icon NVD

Status : Modified

Published: 2026-09-01T20:17:19.290

Modified: 2026-09-02T16:17:20.617

Link: CVE-2026-73718

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:45:05Z

Weaknesses