Description
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affected directory.
Published: 2026-09-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Limited information disclosure leading to access of system files
Action: Assess Impact
AI Analysis

Impact

A vulnerability in the web-based management interface of HPE Networking Fabric Composer allows an unauthenticated remote attacker to read files located within a specific system directory. The flaw results in limited disclosure of sensitive information, potentially revealing configuration data or other private files. No execution or privilege escalation is possible; the impact is restricted to confidentiality, but the exposure of internal files could aid future attacks.

Affected Systems

The affected product is Hewlett Packard Enterprise (HPE) Fabric Composer. No specific version information is provided in the advisory.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting that there are no known widespread exploits at this time. The likely attack vector is a remote web request to the unauthenticated management interface, which does not require authentication. While the risk of exploitation is moderate, the availability of the flaw to unauthenticated users poses a tangible confidentiality threat.

Generated by OpenCVE AI on September 2, 2026 at 01:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Fabric Composer to the latest patch or version that addresses the directory traversal flaw
  • Restrict access to the management interface by implementing network segmentation or firewall rules that limit traffic to authorized IP ranges
  • Enforce authentication and strong access controls on the web management console to prevent unauthenticated access

Generated by OpenCVE AI on September 2, 2026 at 01:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affected directory.
Title Unauthenticated Limited Information Disclosure leads to Data Exposure in HPE Networking Fabric Composer
Weaknesses CWE-552
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:44.813Z

Reserved: 2026-08-13T16:37:26.897Z

Link: CVE-2026-73736

cve-icon Vulnrichment

Updated: 2026-09-01T20:16:28.967Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:21.217

Modified: 2026-09-03T15:12:01.430

Link: CVE-2026-73736

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:44:11Z

Weaknesses
  • CWE-552

    Files or Directories Accessible to External Parties