ZeroHour

CVE-2026-73714

moderate

Authenticated Information Disclosure in HPE Aruba Networking Fabric Composer API

CVSS 3.1
7.6 high
EPSS
<1%p14
Published
()
Modified
AI analysis

HPE Aruba Networking Fabric Composer contains a sensitive information disclosure flaw (CWE-269, improper privilege management) in its API. An attacker who already holds valid low-privilege operator credentials can issue API requests that return data beyond the scope authorized for that role. The disclosed information could be leveraged for further unauthorized access to the fabric management platform or the networks it controls. Only organizations running Fabric Composer — typically deployed as a management platform for Aruba data-center switching fabrics — are affected. As of the latest data there is no public proof-of-concept, it is not in CISA KEV, and EPSS assigns roughly a 0.2% probability of exploitation within 30 days.

What to do: Upgrade Fabric Composer to the fixed release cited in the HPE Aruba Networking security advisory (version details are not in the current data). Until patched, restrict API access to trusted management networks, review and minimize operator-level accounts, and audit API logs for operator-role users retrieving data outside their authorization. Verify whether your deployment exposes the Fabric Composer API beyond an internal management segment.

Affected
Aruba Networks (HPE) HPE Aruba Networking Fabric Composer
Estimated exposure
moderateplausibly in the low thousands of deployments worldwide (exact installed base unknown) — Estimate based on deployment patterns: Fabric Composer is a specialized data-center fabric management platform used primarily by enterprises running Aruba CX data-center switching, generally installed once per data center, and its API is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A sensitive information disclosure vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to access data beyond what is authorized by the user's existing privilege level, potentially leading to further unauthorized access.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

In the news

No ingested article mentions this CVE yet.