Executive brief
HPE Networking Fabric Composer is a network management platform used to configure and monitor fabric switches and network infrastructure. An authenticated operator with low privileges can exploit an API vulnerability to change critical system settings they should not have permission to modify, potentially disrupting network operations or gaining unauthorized access to restricted functions.
Technical details
The vulnerability is a privilege escalation flaw in the API of HPE Networking Fabric Composer that allows authenticated users with low privilege operator roles to modify settings they lack authorization to change. The attack requires valid authentication credentials and is executed through API calls to vulnerable endpoints. Successful exploitation enables an authenticated operator to alter system state and configurations beyond their assigned permissions, potentially compromising the integrity of network management operations. The vulnerability has been assigned CVE-2026-73724 with a CVSS score of 7.1.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed