CVE-2026-73707
Awaiting Analysis Awaiting Analysis - Queue

Privilege Escalation in HPE Networking Fabric Composer API

Vulnerability report for CVE-2026-73707, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Hewlett Packard Enterprise (HPE)

Description

Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform, including changes to the configuration of systems managed by the affected product.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hpe networking_fabric_composer *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a privilege escalation issue in the API of HPE Networking Fabric Composer. It allows an authenticated low-privilege operator user to perform unauthorized state-changing actions that exceed their assigned authorization level. This includes modifying configurations of systems managed by the product.

Impact Analysis

An attacker with low privileges could exploit this to make unauthorized changes to system configurations, potentially disrupting operations or gaining further access. The impact depends on the affected systems but could lead to data breaches or service disruptions.

Compliance Impact

This vulnerability could violate compliance requirements by allowing unauthorized access or changes to sensitive data or systems. GDPR and HIPAA require strict access controls and auditability; such unauthorized actions could lead to non-compliance and potential penalties.

Mitigation Strategies

Immediately restrict API access to authenticated low privilege operator users by reviewing and updating authorization policies. Ensure only necessary administrative actions are permitted for operator roles. Monitor API logs for unusual state-changing actions or unauthorized configuration changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73707. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart