Description
A vulnerability has been identified in the underlying operating system of HPE Networking Fabric Composer that could potentially allow an unauthenticated adjacent actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative access, modify system configurations, and access or manipulate sensitive data.
Published: 2026-09-01
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Administrative Access
Action: Patch Now
AI Analysis

Impact

A vulnerability exists in the operating system underlying HPE Networking Fabric Composer that allows an unauthenticated adjacent actor to bypass existing authentication controls, granting administrative privileges that enable modification of system configurations and manipulation of sensitive data. The impact includes compromise of confidentiality, integrity, and availability of the Fabric Composer environment.

Affected Systems

The affected vendor is Hewlett Packard Enterprise and the product is the Fabric Composer. No version information is specified in the data provided.

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity. The EPSS score of < 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting the current exploitation risk is uncertain but potentially serious. Attackers would likely need proximity on the same physical or logical network and must exploit the authentication bypass to gain administrative control; no publicly known exploits are reported yet.

Generated by OpenCVE AI on September 3, 2026 at 14:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and apply the latest HPE Fabric Composer firmware or software update that addresses the authentication bypass flaw.
  • Enforce multifactor authentication and limit administrative access to trusted IP ranges or devices.
  • Configure network segmentation so that only secured, authorized hosts can reach the Fabric Composer management interface.
  • Continuously monitor logs for failed or suspicious authentication attempts and generate alerts for potential exploitation attempts.

Generated by OpenCVE AI on September 3, 2026 at 14:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
Weaknesses CWE-306
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in the underlying operating system of HPE Networking Fabric Composer that could potentially allow an unauthenticated adjacent actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative access, modify system configurations, and access or manipulate sensitive data.
Title Authentication Bypass in HPE Networking Fabric Composer allows Unauthorized Administrative Access
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T15:32:26.506Z

Reserved: 2026-08-13T16:37:06.403Z

Link: CVE-2026-73726

cve-icon Vulnrichment

Updated: 2026-09-02T15:32:16.793Z

cve-icon NVD

Status : Modified

Published: 2026-09-01T20:17:20.153

Modified: 2026-09-02T16:17:21.570

Link: CVE-2026-73726

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T14:15:06Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function