Junglewise Threat Intelligence

CVE-2026-73735: HPE Networking Fabric Composer privilege escalation in API

CVE-2026-73735 · Severity: medium · CVSS 5.4 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a management platform for network fabric infrastructure. A flaw in its API allows authenticated users with low-level operator permissions to bypass authorization controls and access sensitive information or make changes they should not be permitted to perform, potentially exposing network configuration details or enabling unauthorized modifications.

Technical details

The vulnerability is a privilege escalation flaw in the API of HPE Networking Fabric Composer that fails to properly enforce authorization controls for certain operations. An authenticated user with low-privilege operator role can access information and perform actions beyond their authorized privilege level. The attack requires valid authentication credentials; no unauthenticated network attack is possible. Successful exploitation allows an attacker to retrieve restricted information and make limited unauthorized changes. HPE has released a security update to address this issue.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats