Description
Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to access sensitive information. A successful exploit allows an attacker to access data beyond what is authorized by the user's existing privilege level, which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.
Published: 2026-09-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Disclosure of Sensitive Information
Action: Patch Now
AI Analysis

Impact

The vulnerability in the HPE Networking Fabric Composer API lets an authenticated low‑privilege operator read data that exceeds the permissions originally granted to that user. Exploitation is successful when the attacker uses legitimate API calls, resulting in exposure of sensitive information that can be leveraged for further access to network services supported by Fabric Composer. The CVSS score of 6.5 indicates a moderate severity impact on confidentiality and potentially on the attacker's ability to gain additional footholds.

Affected Systems

The affected product is Hewlett Packard Enterprise’s Fabric Composer. No specific version range is supplied in the CNA data, so all deployed instances of Fabric Composer that expose the vulnerable API may be impacted unless the vendor confirms otherwise.

Risk and Exploitability

The risk is moderate, as reflected by a CVSS score of 6.5 and an EPSS score of less than 1%, indicating a very low but nonzero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to be authenticated with a low‑privilege operator account and to interact with the vulnerable API, making the attack vector an authenticated internal privilege‑misuse scenario rather than a remote unauthenticated one.

Generated by OpenCVE AI on September 3, 2026 at 15:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update HPE Fabric Composer to a version that includes the information‑disclosure fix as soon as it is available from the vendor.
  • Revoke or reduce API access for low‑privilege operator accounts and enforce the principle of least privilege on all Fabric Composer users.
  • Continuously audit privileged accounts and monitor Fabric Composer logs for unauthorized read attempts or anomalous API usage.

Generated by OpenCVE AI on September 3, 2026 at 15:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
Weaknesses CWE-863
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to access sensitive information. A successful exploit allows an attacker to access data beyond what is authorized by the user's existing privilege level, which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.
Title Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer API
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T15:33:09.791Z

Reserved: 2026-08-13T16:37:06.403Z

Link: CVE-2026-73727

cve-icon Vulnrichment

Updated: 2026-09-02T15:33:04.843Z

cve-icon NVD

Status : Modified

Published: 2026-09-01T20:17:20.270

Modified: 2026-09-02T16:17:21.687

Link: CVE-2026-73727

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:30:05Z

Weaknesses