Description
A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to disrupt the availability of the affected interface.
Published: 2026-09-01
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The vulnerability is an authenticated low‑privilege denial of service in the web‑based management interface. A user with operator privileges can trigger the service to crash, leading to loss of availability of the interface and potential interruption of fabric management operations. The weakness corresponds to CWE‑400: Uncontrolled Resource Consumption. The impact is limited to availability; confidentiality and integrity are not directly affected.

Affected Systems

The affected product is Hewlett Packard Enterprise Fabric Composer. The weakness affects all versions of the web‑based management interface that have not been patched. No specific version range is listed, so all exposed installations remain vulnerable until a vendor update is applied.

Risk and Exploitability

The CVSS base score of 3.5 classifies this issue as low severity. With no EPSS data and no listing in the CISA KEV catalog, the likelihood of widespread exploitation appears low. However, the vulnerability requires authentication, so only users with operator or higher privilege on the management console pose a threat. The exploit would involve sending a crafted request to the interface once authenticated, causing the service to terminate.

Generated by OpenCVE AI on September 2, 2026 at 01:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware or patch released by HPE that resolves the denial of service condition in Fabric Composer.
  • Restrict operator accounts to the minimum permissions needed, avoiding privilege on the web interface unless absolutely required.
  • Enable logging and monitor for repeated failed or abnormal request patterns to the web interface and investigate any unexpected downtime.

Generated by OpenCVE AI on September 2, 2026 at 01:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to disrupt the availability of the affected interface.
Title Authenticated Denial of Service Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:52.101Z

Reserved: 2026-08-13T16:38:10.813Z

Link: CVE-2026-73744

cve-icon Vulnrichment

Updated: 2026-09-01T20:07:22.723Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:22.090

Modified: 2026-09-02T15:14:54.143

Link: CVE-2026-73744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:43:58Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption