Description
A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service.
Published: 2026-09-01
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A flaw in the HPE Networking Fabric Composer API allows an authenticated low‑privilege operator user to trigger a denial of service. The vulnerability could let an attacker interrupt the normal operation of the service, causing a loss of availability. It is classified as a resource‑consumption weakness (CWE‑400).

Affected Systems

Hewlett Packard Enterprise Fabric Composer is affected. The flaw applies to any instance of the Fabric Composer API where an authenticated low‑privilege operator has access rights, and no specific version constraints have been published.

Risk and Exploitability

The CVSS score is 3.1, indicating low severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited widespread exploitation. The likely attack vector requires legitimate authentication to the API, after which the attacker can perform repeated or crafted calls to induce a denial of service.

Generated by OpenCVE AI on September 2, 2026 at 02:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the HPE patch or upgrade to a fixed version as documented in the HPE support link
  • Restrict low‑privilege operator accounts from calling the vulnerable API endpoints until the patch is installed
  • Monitor system logs and API traffic for abnormal request patterns that could indicate attempts to trigger a service interruption

Generated by OpenCVE AI on September 2, 2026 at 02:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service.
Title Authenticated Denial of Service Vulnerability in HPE Networking Fabric Composer API
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:54.209Z

Reserved: 2026-08-13T16:38:10.813Z

Link: CVE-2026-73746

cve-icon Vulnrichment

Updated: 2026-09-01T20:07:02.677Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:22.333

Modified: 2026-09-02T15:14:33.160

Link: CVE-2026-73746

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:43:56Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption