Description
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.
Published: 2026-09-01
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: User redirection to malicious URLs
Action: Monitor
AI Analysis

Impact

This vulnerability allows an unauthenticated attacker to influence the web interface of the HPE Networking Fabric Composer to redirect a user to an arbitrary URL. The flaw is an open redirect (CWE-601) that could be leveraged to execute phishing attacks or trick users into visiting malicious sites which might lead to credential theft or further exploitation of the victim’s session.

Affected Systems

HPE Networking Fabric Composer is affected. No specific product versions are listed in the disclosure, so all deployments of the Fabric Composer web interface that are not yet patched are potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.4 indicates a medium severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated request via the publicly accessible web interface, allowing an adversary to craft a redirect URL and lure users into visiting malicious destinations.

Generated by OpenCVE AI on September 2, 2026 at 01:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any HPE patch or update that addresses the open redirect flaw as soon as it becomes available.
  • Restrict access to the Fabric Composer web interface to trusted IP ranges or secure VPNs, limiting the exposure surface for unauthenticated users.
  • Configure a web application firewall or equivalent security controls to detect and block attempted redirect parameters or suspicious request patterns.

Generated by OpenCVE AI on September 2, 2026 at 01:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.
Title Unauthenticated Open Redirect allows URL Manipulation in HPE Networking Fabric Composer Web Interface
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:43.268Z

Reserved: 2026-08-13T16:37:26.897Z

Link: CVE-2026-73734

cve-icon Vulnrichment

Updated: 2026-09-01T20:17:18.869Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:21.013

Modified: 2026-09-03T15:11:52.840

Link: CVE-2026-73734

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:44:14Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')