Description
Denial-of-service vulnerabilities exist in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service.
Published: 2026-09-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

The flaw in the HPE Networking Fabric Composer API permits an authenticated low‑privilege operator to trigger a denial of service. This is a CWE‑400 Uncontrolled Resource Consumption weakness: the system accepts a request that leads to excessive resource usage and service disruption. When successfully exploited, the affected service stops responding, effectively interrupting normal operation for network compositions managed by the application.

Affected Systems

The affected product is Hewlett Packard Enterprise Fabric Composer. No explicit version information is available, implying that the vulnerability may exist in any release that has not yet been patched by HPE.

Risk and Exploitability

With a CVSS score of 6.5 the vulnerability is moderately severe. Exploitation requires authentication, but only low‑privilege permissions, which are commonly granted. The EPSS score is not available, and the CVE is not listed in the CISA KEV catalog. The likely attack vector is remote via the API, and successful exploitation can bring the Fabric Composer service to a halt, impacting availability for users relying on it.

Generated by OpenCVE AI on September 2, 2026 at 01:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any HPE patch or firmware update that addresses the denial of service flaw in the Fabric Composer API.
  • Revoke or reduce low‑privilege API access for operators; enforce strict privilege controls to prevent the vulnerable operation from being invoked.
  • Enable automated monitoring of the Fabric Composer service health, establish alerts for sudden outages, and configure automated restart or failover procedures.

Generated by OpenCVE AI on September 2, 2026 at 01:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Thu, 03 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Denial-of-service vulnerabilities exist in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service.
Title Authenticated Denial of Service Vulnerabilities in HPE Networking Fabric Composer API
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T18:58:00.125Z

Reserved: 2026-08-13T16:37:06.403Z

Link: CVE-2026-73728

cve-icon Vulnrichment

Updated: 2026-09-02T16:23:50.306Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:20.380

Modified: 2026-09-03T15:14:16.910

Link: CVE-2026-73728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:44:26Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption