CVE-2026-73714
moderateAuthenticated Information Disclosure in HPE Aruba Networking Fabric Composer API
HPE Aruba Networking Fabric Composer contains a sensitive information disclosure flaw (CWE-269, improper privilege management) in its API. An attacker who already holds valid low-privilege operator credentials can issue API requests that return data beyond the scope authorized for that role. The disclosed information could be leveraged for further unauthorized access to the fabric management platform or the networks it controls. Only organizations running Fabric Composer — typically deployed as a management platform for Aruba data-center switching fabrics — are affected. As of the latest data there is no public proof-of-concept, it is not in CISA KEV, and EPSS assigns roughly a 0.2% probability of exploitation within 30 days.
What to do: Upgrade Fabric Composer to the fixed release cited in the HPE Aruba Networking security advisory (version details are not in the current data). Until patched, restrict API access to trusted management networks, review and minimize operator-level accounts, and audit API logs for operator-role users retrieving data outside their authorization. Verify whether your deployment exposes the Fabric Composer API beyond an internal management segment.
| Aruba Networks (HPE) HPE Aruba Networking Fabric Composer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A sensitive information disclosure vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to access data beyond what is authorized by the user's existing privilege level, potentially leading to further unauthorized access.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.