Junglewise Threat Intelligence

CVE-2026-73746: HPE Networking Fabric Composer API denial of service

CVE-2026-73746 · Severity: low · CVSS 3.1 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a management tool used to configure and oversee network fabric infrastructure. A denial-of-service vulnerability in its API allows authenticated low-privilege operators to disrupt service availability by causing the system to become unresponsive, impacting network operations.

Technical details

A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that can be triggered by authenticated low-privilege operator users. The vulnerability allows an attacker with valid credentials to send specially crafted API requests that cause the service to become unavailable. Exploitation requires authentication, limiting the attack surface to users with legitimate access to the system. A patch or mitigation guidance is expected to be available from HPE.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats