Junglewise Threat Intelligence

CVE-2026-73737: HPE Networking Fabric Composer unauthenticated path traversal in API

CVE-2026-73737 · Severity: medium · CVSS 4.8 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network management platform used to configure and orchestrate fabric switches. This vulnerability allows unauthenticated attackers on an adjacent network segment to manipulate files through an API endpoint, potentially altering critical network configurations without proper authorization.

Technical details

The vulnerability is an unauthenticated path traversal flaw in an API endpoint of HPE Networking Fabric Composer. It allows attackers to bypass authentication controls and traverse the file system to access or manipulate user-generated files. The attack requires network adjacency but no authentication credentials. Successful exploitation could lead to unauthorized modifications of critical system configurations, though the advisory notes certain preconditions outside the attacker's control must be met. Patches are expected to be available from HPE.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats