CVE-2026-73718
moderateCSRF Information Disclosure in HPE Aruba Networking Fabric Composer
CVE-2026-73718 is a cross-site request forgery flaw (CWE-352) in the web-based management interface of HPE Networking Fabric Composer (HPE Aruba Networking Fabric Composer). An unauthenticated remote attacker can exploit it by convincing an authenticated interface user to interact with a specially crafted URL, causing the user's browser session to disclose sensitive information. The flaw has high confidentiality impact only (no integrity or availability impact per the CVSS vector), but the retrieved information could potentially be used to gain further access to network services supported by Fabric Composer. Any organization running the Fabric Composer web interface with authenticated users is exposed; the available data does not specify affected version ranges. There is no known public proof of concept, the issue is not in CISA's KEV catalog, and EPSS assigns roughly a 0.2% probability of exploitation within 30 days.
What to do: Apply the fixed release identified in HPE/Aruba's security bulletin for CVE-2026-73718 (version numbers are not included in the data available here). Until patched, restrict the Fabric Composer web interface to trusted management networks and instruct users not to follow untrusted links while logged into the interface. No in-the-wild exploitation, public PoC, or KEV listing is known, so urgent exposure is currently low, but patches should still be scheduled promptly since the flaw is rated High severity.
| arubanetworks (HPE Aruba) Fabric Composer (web-based management interface) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to access sensitive information if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-352
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.