Junglewise Threat Intelligence

CVE-2026-73726: HPE Networking Fabric Composer authentication bypass in operating system

CVE-2026-73726 · Severity: medium · CVSS 6.8 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network management platform used to configure and manage fabric switches and infrastructure. A vulnerability in its underlying operating system allows an unauthenticated attacker on an adjacent network to bypass authentication controls and gain administrative access, enabling them to modify configurations, disrupt network operations, and access sensitive data.

Technical details

The vulnerability is an authentication bypass in the underlying operating system of HPE Networking Fabric Composer. It allows an unauthenticated adjacent network actor to circumvent existing authentication controls without requiring valid credentials. Successful exploitation grants administrative access, enabling attackers to modify system configurations, access or manipulate sensitive data, and potentially compromise the entire fabric management infrastructure. The attack requires network adjacency but no user interaction or prior authentication. Patches are available from HPE.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats