Description
A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to upstream AFC dependencies to view sensitive information. Successful exploitation could allow an attacker to access data beyond what is authorized by the user's existing privilege level, potentially leading to further unauthorized access.
Published: 2026-09-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Patch ASAP
AI Analysis

Impact

An authenticated low privilege operator with local access to upstream AFC dependencies can exploit a flaw in the operating system of HPE Networking Fabric Composer to view sensitive information that exceeds the operator’s authorized level. This disclosure could provide an attacker with data that may facilitate further unauthorized actions against the system.

Affected Systems

The vulnerability affects Hewlett Packard Enterprise's Fabric Composer product. No specific version numbers are disclosed, so all installations should be evaluated.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity condition. The EPSS score of <1% suggests exploitation is unlikely but not impossible, and the vulnerability is not listed in CISA KEV, implying it has not been reported as a known exploited vulnerability. The likely attack vector requires local authenticated access, so the risk is confined to environments where low‑privilege operators possess local access to upstream dependencies, and no public remote exploitation has been reported.

Generated by OpenCVE AI on September 3, 2026 at 15:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Fabric Composer security update when it becomes available
  • Restrict low‑privilege operator accounts from accessing upstream AFC dependencies
  • Remove or elevate permissions for unnecessary local access accounts and monitor for anomalous activity

Generated by OpenCVE AI on September 3, 2026 at 15:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Thu, 03 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 03 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to upstream AFC dependencies to view sensitive information. Successful exploitation could allow an attacker to access data beyond what is authorized by the user's existing privilege level, potentially leading to further unauthorized access.
Title Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T18:57:54.611Z

Reserved: 2026-08-13T16:37:06.404Z

Link: CVE-2026-73729

cve-icon Vulnrichment

Updated: 2026-09-02T16:22:05.029Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:20.490

Modified: 2026-09-03T15:13:53.723

Link: CVE-2026-73729

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:45:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management