Junglewise Threat Intelligence

CVE-2026-73710: HPE Networking Fabric Composer API endpoint denial of service

CVE-2026-73710 · Severity: high · CVSS 8.2 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network management platform that controls and monitors fabric switching infrastructure in data centers. An unauthenticated remote attacker can exploit a vulnerability in its API endpoint to cause a denial of service, disrupting network operations and requiring manual intervention to restore the system. The attacker may also make limited unauthorized modifications to the underlying operating system.

Technical details

The vulnerability exists in an API endpoint of HPE Networking Fabric Composer and can be exploited by an unauthenticated remote attacker over the network. Successful exploitation allows an attacker to conduct a denial of service attack, disrupting system availability, and potentially make limited unauthorized modifications to the underlying operating system. The vulnerability requires network reachability to the affected API endpoint but does not require authentication or user interaction. Manual intervention is required to restore functionality after exploitation. Patch or workaround details are available through HPE support documentation.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats