Junglewise Threat Intelligence

CVE-2026-73714: HPE Networking Fabric Composer API information disclosure

CVE-2026-73714 · Severity: high · CVSS 7.6 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network management platform used to configure and monitor fabric-based data center networks. A vulnerability in its API allows authenticated operators to view sensitive data and configuration details beyond their assigned permission level, potentially enabling lateral movement and unauthorized access to network infrastructure.

Technical details

The vulnerability is an information disclosure flaw in the API of HPE Networking Fabric Composer that affects privilege boundary enforcement. An authenticated user with low-privilege operator credentials can bypass authorization checks to access data reserved for higher-privilege accounts. The attack requires valid API authentication; no network-level access controls are bypassed. Successful exploitation allows an attacker to enumerate sensitive configuration, credentials, or operational data that could facilitate further attacks on the fabric infrastructure. HPE has released patches; check support portal hpesbnw05133en_us for details.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats