Description
A vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to view some system files. Successful exploitation could allow an attacker to access limited data beyond what is authorized by the user's existing privilege level.
Published: 2026-09-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authenticated Limited Data Exposure
Action: Apply Patch
AI Analysis

Impact

The HPE Networking Fabric Composer API contains an access‑control flaw that lets an authenticated operator with low privileges read certain system files beyond the authorized scope, potentially exposing sensitive configuration data.

Affected Systems

Hewlett Packard Enterprise’s Fabric Composer product is affected. No specific version information was listed in the advisory, so any deployed instance of Fabric Composer may be vulnerable until the vendor releases a fix.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. An attacker would need legitimate credentials for a low‑privilege operator account and access to the API, making it an authenticated attack. Once exploited, the attacker can read selected system files but cannot execute arbitrary code or modify data, so the risk is confined to data exposure.

Generated by OpenCVE AI on September 2, 2026 at 01:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the HPE Fabric Composer security patch that corrects the access control check for file reads.
  • Limit operator roles to the minimum permissions required for their duties and disable any excess file‑access rights.
  • Enable detailed API activity logging and review logs for abnormal file‑read requests to detect potential abuse.

Generated by OpenCVE AI on September 2, 2026 at 01:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to view some system files. Successful exploitation could allow an attacker to access limited data beyond what is authorized by the user's existing privilege level.
Title Authenticated Limited File Read allows Data Exposure in HPE Networking Fabric Composer API
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:49.012Z

Reserved: 2026-08-13T16:38:10.812Z

Link: CVE-2026-73741

cve-icon Vulnrichment

Updated: 2026-09-01T20:11:15.249Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:21.747

Modified: 2026-09-03T15:12:37.333

Link: CVE-2026-73741

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:44:03Z

Weaknesses