Junglewise Threat Intelligence

CVE-2026-73734: HPE Networking Fabric Composer open redirect in management interface

CVE-2026-73734 · Severity: medium · CVSS 5.4 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a web-based management interface for network fabric infrastructure. An unauthenticated attacker can exploit an open redirect vulnerability to trick users into visiting malicious websites, potentially compromising credentials or distributing malware without needing any authentication.

Technical details

The vulnerability is an open redirect flaw in the web-based management interface of HPE Networking Fabric Composer. An unauthenticated remote attacker can craft a URL with an arbitrary redirect target, causing users who access the legitimate interface to be redirected to an attacker-controlled website. The attack requires user interaction (clicking a malicious link) but no authentication. This could be leveraged in phishing campaigns to harvest credentials or deliver malware while appearing to originate from a trusted network management tool.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats