Description
Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.
Published: 2026-09-01
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via API
Action: Patch Now
AI Analysis

Impact

Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. A successful attack allows an authenticated low‑privilege operator to alter the state of specific configuration settings that should be restricted to higher‑privilege users. This can expand the attacker’s control within the system, potentially enabling further compromises such as privilege elevation, service disruption, or unauthorized network changes. The weakness arises from inadequate enforcement of access controls that fails to limit state‑changing operations to authorized roles.

Affected Systems

The affected product is Hewlett Packard Enterprise Fabric Composer. No particular version information is supplied, so any installation that exposes the vulnerable API is at risk until a patch is applied.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. The EPSS score is reported as less than 1 %, suggesting a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires only authenticated access by a low‑privilege operator, the likelihood of exploitation is relatively high in environments where such users have API access. An attacker can potentially exploit the API directly, bypassing authorization checks, and modify configuration values that should be restricted, thereby escalating privileges within the system.

Generated by OpenCVE AI on September 3, 2026 at 15:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE Fabric Composer patch that fixes the access control issue.
  • Restrict API access for low‑privilege operator accounts, ensuring only administrators can modify sensitive settings.
  • Enable detailed audit logging for API calls that modify configuration to detect unauthorized attempts.

Generated by OpenCVE AI on September 3, 2026 at 15:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-732

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
Weaknesses CWE-863
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
CWE-732

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.
Title Authenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric Composer
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T15:31:07.825Z

Reserved: 2026-08-13T16:37:06.403Z

Link: CVE-2026-73724

cve-icon Vulnrichment

Updated: 2026-09-02T15:30:59.387Z

cve-icon NVD

Status : Modified

Published: 2026-09-01T20:17:19.947

Modified: 2026-09-02T16:17:21.327

Link: CVE-2026-73724

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:45:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-863

    Incorrect Authorization