CVE-2026-73715
nicheUnauthenticated DoS in HPE Networking Fabric Composer API
CVE-2026-73715 is a denial-of-service flaw in the API of HPE Networking Fabric Composer (Aruba Networks), classified as uncontrolled resource consumption (CWE-400). An unauthenticated remote attacker can trigger it by sending crafted requests directly to the exposed API, with no user interaction or credentials required. Successful exploitation disrupts the availability of the affected interface; the CVSS vector confirms no confidentiality or integrity impact, only high availability impact. Organizations running HPE/Aruba Fabric Composer to manage their switching fabric are the affected population. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at only 0.4%, indicating no observed exploitation so far.
What to do: Monitor the HPE/Aruba security advisory for CVE-2026-73715 and upgrade Fabric Composer to the fixed release it specifies (no fixed version is given in the current data). Until patched, restrict network access to the Fabric Composer API to trusted management networks and remove any direct internet exposure of the interface. Since Fabric Composer orchestrates the switching fabric, consider the operational impact of a management-plane outage and have a fallback management method ready.
| HPE (Aruba Networks) Networking Fabric Composer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to disrupt the availability of the affected interface.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.