Junglewise Threat Intelligence

CVE-2026-73733: HPE Networking Fabric Composer API authentication bypass

CVE-2026-73733 · Severity: medium · CVSS 5.4 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network management platform used to operate and configure fabric-based data center networks. A flaw in its API allows low-privilege users to bypass authentication controls and retain access to the system even after their credentials should have been revoked, potentially enabling unauthorized management of critical network infrastructure.

Technical details

The vulnerability is an authentication bypass in the API of HPE Networking Fabric Composer that allows an authenticated, low-privilege operator user to circumvent existing authentication controls. The attack requires prior authentication (the attacker must already have valid credentials), and successful exploitation enables an attacker to maintain access to the affected system after legitimate access should have been revoked. The specific mechanism of the bypass is not detailed in the available reference material, but the impact is limited to retaining access rather than escalating privileges.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats