Junglewise Threat Intelligence

CVE-2026-73745: HPE Networking Fabric Composer API information disclosure

CVE-2026-73745 · Severity: low · CVSS 3.1 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a management platform for network fabric infrastructure. An unauthenticated attacker can access sensitive information through an exposed API endpoint, potentially revealing details about internal services and configurations that could be leveraged in follow-up attacks.

Technical details

A vulnerability in an API endpoint of HPE Networking Fabric Composer allows unauthenticated remote access to sensitive information. The issue stems from insufficient access controls on the affected endpoint, allowing attackers to enumerate internal services and workflows without authentication. The vulnerability is network-reachable and requires no user interaction or valid credentials. Successful exploitation grants visibility into system architecture and services, which can facilitate reconnaissance for subsequent targeted attacks. The vendor has released patches to restrict API endpoint access.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats