CVE-2026-73706
nicheUnauthenticated API access flaw in HPE Aruba Networking Fabric Composer
CVE-2026-73706 is a missing-authentication flaw (CWE-306) in the API of HPE Aruba Networking Fabric Composer, HPE's orchestration platform for Aruba data-center fabrics. Because the affected API endpoints accept unauthenticated network requests, a remote attacker needs no credentials or user interaction to trigger the issue. A successful attacker gains limited system information (insight into internal services and workflows) and can change the state of certain settings, potentially disrupting the normal operation of the affected service. Only organizations running HPE Aruba Networking Fabric Composer are affected; the 8.6 (High) CVSS score reflects network exploitation with low confidentiality and availability impact but high integrity impact. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS estimates only a 0.3% chance of exploitation within 30 days.
What to do: Upgrade Fabric Composer to the fixed release identified in the HPE security advisory (fixed version not stated in this data). Until patching, restrict API access to trusted management networks and review managed settings for unexpected or unauthorized changes. Given no known PoC or in-the-wild exploitation, urgent exposure beyond patching is not indicated.
| HPE (Aruba Networks) HPE Aruba Networking Fabric Composer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to obtain limited system information and to change the state of certain settings of a vulnerable system. Successful exploitation could allow an attacker to gain insight into internal services and workflows and to make unauthorized changes that may disrupt the normal operation of the affected service.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.