Junglewise Threat Intelligence

CVE-2026-73708: HPE Networking Fabric Composer privilege escalation in API

CVE-2026-73708 · Severity: high · CVSS 8.3 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network fabric management platform. A flaw in its API allows authenticated low-privilege operators to escalate their access and modify network settings beyond their authorization level, potentially allowing unauthorized changes to critical network infrastructure.

Technical details

A business logic vulnerability exists in the API of HPE Networking Fabric Composer that allows privilege escalation. The vulnerability can be exploited by an authenticated low-privilege user to gain elevated privileges and modify settings that should be restricted by their current access level. The attack requires valid authentication credentials but allows an operator to exceed their authorized scope. No patch status is explicitly confirmed in the provided advisory text.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats