Junglewise Threat Intelligence

CVE-2026-73742: HPE Networking Fabric Composer API spoofing in request attribution

CVE-2026-73742 · Severity: medium · CVSS 4.3 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a network management platform used to configure and monitor fabric switches. A vulnerability in its API allows authenticated operators to falsify the source address of their requests, causing audit logs to record incorrect attribution. While exploitation requires valid credentials and causes no direct service disruption, it undermines accountability and could facilitate undetected malicious activity by privileged insiders.

Technical details

The vulnerability is an API request attribution spoofing issue in HPE Networking Fabric Composer, where an authenticated low-privilege operator user can craft requests to manipulate the source address attribution mechanism. The flaw resides in an API endpoint that fails to properly validate or enforce the source address of incoming requests, allowing an attacker to inject false source identifiers. Attack requires valid authentication credentials but no elevated privileges. Successful exploitation results in inaccurate audit log entries that misattribute actions to other users or systems, degrading accountability and forensic capabilities. Patches from HPE are expected to address this endpoint validation logic.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats