Description
An unauthenticated path traversal vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to manipulate user generated files, potentially leading to unauthorized changes in critical system configurations, if certain preconditions outside of the attacker's control are met.
Published: 2026-09-01
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized File Modification
Action: Patch
AI Analysis

Impact

An unauthenticated path traversal flaw exists in the API endpoint of HPE Networking Fabric Composer. An attacker who can reach the API from an adjacent network segment could potentially write user‑generated files to arbitrary locations under the service’s directory. If the attacker succeeds, critical system configuration files could be altered, compromising the integrity and availability of the Fabric Composer product. The weakness is identified as CWE‑22, which addresses path traversal vulnerabilities that allow unintended file access.

Affected Systems

The affected vendor is Hewlett Packard Enterprise, product Fabric Composer. No specific version range is disclosed, so all installations of Fabric Composer that expose the vulnerable API endpoint are potentially impacted.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated access to the exposed API endpoint from an adjacent network. Exploitation would require the attacker to be within network range and to target the vulnerable endpoint; no privileged context or user authentication is needed."

Generated by OpenCVE AI on September 2, 2026 at 01:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the HPE Fabric Composer security update that addresses the path traversal flaw.
  • If a patch is unavailable, isolate the API endpoint through firewall or network segmentation so only trusted hosts can reach it.
  • Disable or restrict the vulnerable API endpoint in the Fabric Composer configuration until a patch can be applied.
  • Monitor access logs for unauthorized file modification attempts and verify that any changes are legitimate.
  • Disable or block remote access to the Fabric Composer service from untrusted networks until remediation is complete.

Generated by OpenCVE AI on September 2, 2026 at 01:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description An unauthenticated path traversal vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to manipulate user generated files, potentially leading to unauthorized changes in critical system configurations, if certain preconditions outside of the attacker's control are met.
Title Unauthenticated Path Traversal in HPE Networking Fabric Composer API Endpoint Allows Unauthorized File Modification
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:45.708Z

Reserved: 2026-08-13T16:37:26.897Z

Link: CVE-2026-73737

cve-icon Vulnrichment

Updated: 2026-09-01T20:15:46.323Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:21.320

Modified: 2026-09-03T15:12:11.253

Link: CVE-2026-73737

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:44:09Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')