Junglewise Threat Intelligence

CVE-2026-73738: HPE Networking Fabric Composer information disclosure in underlying OS

CVE-2026-73738 · Severity: medium · CVSS 4.7 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network management and configuration tool used to operate and monitor fabric networks. A vulnerability in its underlying operating system allows authenticated operators with low privileges and local system access to view sensitive information that could enable privilege escalation or further compromise of the affected device.

Technical details

This vulnerability exists in the underlying operating system layer of HPE Networking Fabric Composer rather than in the application itself. An authenticated low-privilege operator with local access can exploit the flaw to read sensitive system information. The vulnerability requires both local system access and valid authentication credentials. Successful exploitation could provide information disclosure that facilitates privilege escalation attacks against the affected system.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats