Junglewise Threat Intelligence

CVE-2026-73724: HPE Networking Fabric Composer privilege escalation in API

CVE-2026-73724 · Severity: high · CVSS 7.1 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network management platform used to configure and monitor fabric switches and network infrastructure. An authenticated operator with low privileges can exploit an API vulnerability to change critical system settings they should not have permission to modify, potentially disrupting network operations or gaining unauthorized access to restricted functions.

Technical details

The vulnerability is a privilege escalation flaw in the API of HPE Networking Fabric Composer that allows authenticated users with low privilege operator roles to modify settings they lack authorization to change. The attack requires valid authentication credentials and is executed through API calls to vulnerable endpoints. Successful exploitation enables an authenticated operator to alter system state and configurations beyond their assigned permissions, potentially compromising the integrity of network management operations. The vulnerability has been assigned CVE-2026-73724 with a CVSS score of 7.1.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats