Junglewise Threat Intelligence

CVE-2026-73730: HPE Networking Fabric Composer API privilege escalation

CVE-2026-73730 · Severity: medium · CVSS 6.5 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network management platform used to configure and monitor fabric switches and related infrastructure. A privilege escalation flaw in its API allows authenticated low-privilege operators to change system settings they should not have access to, potentially compromising network configuration integrity and availability.

Technical details

A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer that fails to properly enforce role-based access controls. An authenticated user with low-privilege operator credentials can make API calls to modify system settings that should be restricted to higher-privileged roles. The vulnerability requires valid authentication and network access to the API; no unauthenticated exploitation is possible. Successful exploitation allows an attacker to alter critical system configurations, potentially leading to network disruption or unauthorized changes to fabric management settings. Patches are available from HPE.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats