Junglewise Threat Intelligence

CVE-2026-73715: HPE Networking Fabric Composer API denial of service

CVE-2026-73715 · Severity: high · CVSS 7.5 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network management platform used to configure and control fabric switches and network infrastructure. A vulnerability in its API allows an unauthenticated attacker to disrupt the service, potentially causing network outages and operational downtime for organizations relying on this management interface.

Technical details

The vulnerability exists in the API component of HPE Networking Fabric Composer and can be exploited remotely without authentication. An attacker can send specially crafted API requests to trigger a denial of service condition that disrupts the availability of the affected interface. The attack requires only network reachability to the API endpoint and no prior authentication. Successful exploitation would render the management interface unavailable, though the underlying network infrastructure may continue to operate.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats