ZeroHour

CVE-2026-73710

niche

Unauthenticated API Endpoint DoS in HPE Aruba Networking Fabric Composer

CVSS 3.1
8.2 high
EPSS
<1%p19
Published
()
Modified
AI analysis

HPE (Aruba) Networking Fabric Composer contains a missing-authentication flaw (CWE-306) in one of its API endpoints, meaning requests to that interface do not require any credentials. An unauthenticated remote attacker can send crafted requests to this API endpoint to disrupt the availability of the affected system and make limited unauthorized modifications to the underlying operating system, with recovery requiring manual intervention. Any organization running HPE Aruba Networking Fabric Composer is affected, although the advisory data available here does not specify which versions are impacted or identify a fixed release. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only about a 0.3% probability of exploitation within 30 days.

What to do: Review the HPE security bulletin for CVE-2026-73710 and upgrade Fabric Composer to the fixed release it specifies, since no version numbers are given in the advisory data available here. Until patching, restrict access to the Fabric Composer API endpoint to trusted management networks using ACLs or firewall rules, and be prepared for manual recovery because successful attacks can make limited OS changes and take the system down.

Affected
HPE (Aruba Networks) Networking Fabric Composer
Estimated exposure
nichelikely on the order of hundreds to a few thousand deployments worldwide, with most management APIs kept on internal management networks — Fabric Composer is a specialized HPE data center fabric-management appliance with no published install counts, so the estimate rests on its niche enterprise deployment pattern (one management instance per data center fabric) rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerabilities in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to make limited unauthorized modifications to the underlying operating system and disrupt the availability of the affected system, requiring manual intervention to restore functionality.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

In the news

No ingested article mentions this CVE yet.