ZeroHour

CVE-2026-73706

niche

Unauthenticated API access flaw in HPE Aruba Networking Fabric Composer

CVSS 3.1
8.6 high
EPSS
<1%p20
Published
()
Modified
AI analysis

CVE-2026-73706 is a missing-authentication flaw (CWE-306) in the API of HPE Aruba Networking Fabric Composer, HPE's orchestration platform for Aruba data-center fabrics. Because the affected API endpoints accept unauthenticated network requests, a remote attacker needs no credentials or user interaction to trigger the issue. A successful attacker gains limited system information (insight into internal services and workflows) and can change the state of certain settings, potentially disrupting the normal operation of the affected service. Only organizations running HPE Aruba Networking Fabric Composer are affected; the 8.6 (High) CVSS score reflects network exploitation with low confidentiality and availability impact but high integrity impact. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS estimates only a 0.3% chance of exploitation within 30 days.

What to do: Upgrade Fabric Composer to the fixed release identified in the HPE security advisory (fixed version not stated in this data). Until patching, restrict API access to trusted management networks and review managed settings for unexpected or unauthorized changes. Given no known PoC or in-the-wild exploitation, urgent exposure beyond patching is not indicated.

Affected
HPE (Aruba Networks) HPE Aruba Networking Fabric Composer
Estimated exposure
nicheLow thousands of enterprise deployments worldwide (specialized data-center fabric orchestration appliance, typically on internal management networks) — Fabric Composer is a niche orchestration virtual appliance tied to Aruba CX data-center switching deployments and is usually placed on internal management networks, so its install and exposed base is far smaller than mainstream Aruba…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to obtain limited system information and to change the state of certain settings of a vulnerable system. Successful exploitation could allow an attacker to gain insight into internal services and workflows and to make unauthorized changes that may disrupt the normal operation of the affected service.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

In the news

No ingested article mentions this CVE yet.