CVE-2026-73718
Awaiting Analysis Awaiting Analysis - Queue

Information Disclosure in HPE Networking Fabric Composer

Vulnerability report for CVE-2026-73718, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Hewlett Packard Enterprise (HPE)

Description

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to access sensitive information if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hpe networking_fabric_composer *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an unauthenticated remote attacker to access sensitive information by tricking an authenticated user into clicking a specially crafted URL in the HPE Networking Fabric Composer web interface. Exploitation could lead to data exposure that might help the attacker gain further access to network services.

Detection Guidance

This vulnerability requires user interaction to exploit, so detection may involve monitoring for suspicious URLs accessed by authenticated users. Check web server logs for unusual GET requests containing sensitive parameters or crafted URLs. Inspect network traffic for outbound connections initiated by the HPE Networking Fabric Composer interface.

Impact Analysis

If exploited, this vulnerability could allow attackers to steal sensitive data, potentially leading to unauthorized access to network services managed by HPE Networking Fabric Composer. Users of the interface may unknowingly expose confidential information.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, violating compliance requirements like GDPR or HIPAA, which mandate strict protection of sensitive information. Organizations may face legal penalties or reputational damage if exploited.

Mitigation Strategies

Apply patches or updates from HPE as soon as they become available. Restrict access to the web-based management interface to trusted networks or IP addresses. Educate users to avoid clicking on untrusted links or URLs. Monitor for any unusual activity or unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73718. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart