Junglewise Threat Intelligence

CVE-2026-73736: HPE Networking Fabric Composer path traversal in web interface

CVE-2026-73736 · Severity: medium · CVSS 5.3 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a web-based management tool for enterprise network fabric infrastructure. An unauthenticated attacker can read arbitrary files on the system through the management interface, potentially exposing sensitive configuration data, credentials, or system information that could be used for further attacks.

Technical details

This vulnerability is a path traversal/directory traversal flaw in the web-based management interface of HPE Networking Fabric Composer. The vulnerability allows an unauthenticated remote attacker to read arbitrary files within the affected directory by manipulating file path parameters. No authentication is required to exploit this issue, making it remotely exploitable by any network-accessible user. Successful exploitation enables an attacker to access sensitive system files and configuration information. HPE has released patches to address this vulnerability.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats