Junglewise Threat Intelligence

CVE-2026-73739: HPE Networking Fabric Composer cleartext sensitive information disclosure in API

CVE-2026-73739 · Severity: medium · CVSS 4.4 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network management platform used to configure and manage fabric switches in enterprise environments. A vulnerability in its API allows administrators to access sensitive information in cleartext, exposing credentials and other protected data that could be leveraged for lateral movement or further attacks within the network infrastructure.

Technical details

The vulnerability exists in the API of HPE Networking Fabric Composer and permits cleartext exposure of sensitive information. An attacker with administrative privileges can exploit this flaw to retrieve sensitive data that should remain protected within the system. The attack vector requires network access to the API and valid administrative credentials. A successful exploitation enables disclosure of sensitive information such as credentials or configuration secrets, facilitating further compromise of the fabric environment. Patches or mitigations should be available from HPE.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats