Description
A vulnerability exists in the API of HPE Networking Fabric Composer that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve sensitive information that was expected to remain protected within the affected system.
Published: 2026-09-01
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Assess Impact
AI Analysis

Impact

The flaw resides in the HPE Networking Fabric Composer API, allowing an authenticated attacker with administrative privileges to retrieve sensitive information in cleartext. This breach of confidentiality is an instance of CWE‑200: Information Exposure, exposing data that should remain protected within the system.

Affected Systems

The vulnerability affects Hewlett Packard Enterprise Fabric Composer. No specific software versions are enumerated, so all deployments of the product should be examined for exposure.

Risk and Exploitability

The CVSS score of 4.4 denotes moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in CISA KEV, indicating that it is not widely exploited at this time. The attack requires authenticated administrative access, so the risk is scoped to organizations where such privileges may have been compromised or where segregation of duties is insufficient.

Generated by OpenCVE AI on September 2, 2026 at 01:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Consult the HPE support portal (https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US) for any available patch or update addressing the disclosed issue.
  • Apply any released patch or update to the Fabric Composer installation as soon as possible to eliminate the disclosure path.
  • Restrict administrative privileges to essential personnel only and enforce least‑privilege policies to reduce the chance of an attacker gaining the required access in the future.

Generated by OpenCVE AI on September 2, 2026 at 01:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability exists in the API of HPE Networking Fabric Composer that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve sensitive information that was expected to remain protected within the affected system.
Title Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer API
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:47.371Z

Reserved: 2026-08-13T16:37:26.897Z

Link: CVE-2026-73739

cve-icon Vulnrichment

Updated: 2026-09-01T20:14:04.638Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:21.530

Modified: 2026-09-03T15:12:32.043

Link: CVE-2026-73739

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:44:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor