Description
Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to access some information beyond their privilege level. Successful exploitation could allow an attacker to obtain limited information and/or make limited changes beyond what is authorized by the user's existing privilege level.
Published: 2026-09-01
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Apply
AI Analysis

Impact

Vulnerabilities in HPE Networking Fabric Composer’s API allow an authenticated low‑privilege operator to read data and perform operations beyond the permissions granted to that role. The flaw results in limited information disclosure and the possibility of constrained configuration changes that should be denied, reflecting a weakness in access control (CWE‑552).

Affected Systems

The affected product is Hewlett Packard Enterprise’s Fabric Composer networking appliance. The advisory does not list specific firmware or software versions, so administrators should verify that their deployed instance is covered by the latest vendor updates.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and the absence of an EPSS value as well as no listing in the CISA KEV catalog suggest that large‑scale exploitation is currently unlikely. Because the exploit requires authenticated access, the threat is limited to organizations that do not enforce strict role segregation. Even so, the most effective mitigation is to obtain and deploy the vendor’s firmware patch or otherwise tighten API permissions.

Generated by OpenCVE AI on September 2, 2026 at 01:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain the latest HPE Networking Fabric Composer firmware update that addresses the API access control issue.
  • Upgrade the appliance to the patched version.
  • If an immediate upgrade is not possible, restrict low‑privilege users from the vulnerable API endpoints and monitor for anomalous activity.

Generated by OpenCVE AI on September 2, 2026 at 01:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to access some information beyond their privilege level. Successful exploitation could allow an attacker to obtain limited information and/or make limited changes beyond what is authorized by the user's existing privilege level.
Title Authenticated Access Control Vulnerabilities allow Information Disclosure in HPE Networking Fabric Composer API
Weaknesses CWE-552
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:44.067Z

Reserved: 2026-08-13T16:37:26.897Z

Link: CVE-2026-73735

cve-icon Vulnrichment

Updated: 2026-09-01T20:16:52.467Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:21.110

Modified: 2026-09-03T15:12:06.003

Link: CVE-2026-73735

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:44:12Z

Weaknesses
  • CWE-552

    Files or Directories Accessible to External Parties