Description
A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to obtain sensitive information. Successful exploitation could allow an attacker to retrieve sensitive data which could be used to gain further unauthorized access to the affected system and to other systems it interacts with.
Published: 2026-09-01
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Assess Impact
AI Analysis

Impact

A flaw in the base operating system of the HPE Networking Fabric Composer permits an authenticated user with limited privileges, who has local access, to obtain sensitive information. The vulnerability falls under CWE-200 and could enable the attacker to read data that may be used to reach further into the system or other networks.

Affected Systems

The vulnerability affects HPE Networking Fabric Composer. No specific product versions are listed, so all releases without the provided fix are potentially impacted.

Risk and Exploitability

The CVSS score of 5.6 indicates moderate severity. Because the EPSS score is not available and the issue is not listed in CISA KEV, the likelihood of widespread exploitation is uncertain. The attack vector is local, requiring authentication on the system; an attacker must be able to log into the Composer with a low‑privilege account to leverage the flaw.

Generated by OpenCVE AI on September 2, 2026 at 01:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict local operator accounts to the least privileges necessary.
  • Audit access logs for anomalous activity and enforce stricter authentication controls.
  • Review and, if possible, disable unnecessary services or privileges on the Fabric Composer to reduce the attack surface.

Generated by OpenCVE AI on September 2, 2026 at 01:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to obtain sensitive information. Successful exploitation could allow an attacker to retrieve sensitive data which could be used to gain further unauthorized access to the affected system and to other systems it interacts with.
Title Local Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:41.740Z

Reserved: 2026-08-13T16:37:26.896Z

Link: CVE-2026-73732

cve-icon Vulnrichment

Updated: 2026-09-01T20:18:52.021Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:20.807

Modified: 2026-09-03T15:11:25.420

Link: CVE-2026-73732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:44:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor