Description
Authentication bypasses in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to circumvent existing authentication controls. Successful exploitation could allow an attacker to retain limited access to the affected system after that access should have been revoked.
Published: 2026-09-01
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass enabling retained limited access to the system after revocation
Action: Apply Patch
AI Analysis

Impact

Authentication bypass exists in the API of HPE Networking Fabric Composer that allows an authenticated low‑privilege operator to circumvent existing authentication controls. The vulnerability is a classic authentication failure (CWE‑287). Successful exploitation can let an attacker keep limited access to the system even after the legitimate session should have been revoked.

Affected Systems

The affected platform is Hewlett Packard Enterprise Fabric Composer. No specific version information is provided in the data.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation. The likely attack vector requires an authenticated user with low privileges who can access the API, so the risk is most acute in environments where such operators have broader rights or where API access is not tightly scoped.

Generated by OpenCVE AI on September 2, 2026 at 01:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify if an updated firmware or software build from HPE includes a fix for the authentication bypass and install it immediately
  • Re‑evaluate operator roles and apply the principle of least privilege to limit API usage to only those who require it
  • Configure API session timeouts and enforce strict access controls to minimize the duration of continued unauthorized access

Generated by OpenCVE AI on September 2, 2026 at 01:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Authentication bypasses in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to circumvent existing authentication controls. Successful exploitation could allow an attacker to retain limited access to the affected system after that access should have been revoked.
Title Authentication Bypasses in API allow Continued Authenticated Access in HPE Networking Fabric Composer
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:42.500Z

Reserved: 2026-08-13T16:37:26.896Z

Link: CVE-2026-73733

cve-icon Vulnrichment

Updated: 2026-09-01T20:17:58.307Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:20.910

Modified: 2026-09-03T15:11:32.573

Link: CVE-2026-73733

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:44:16Z

Weaknesses