CVE-2026-73737
Awaiting Analysis Awaiting Analysis - Queue

Path Traversal in HPE Networking Fabric Composer API

Vulnerability report for CVE-2026-73737, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Hewlett Packard Enterprise (HPE)

Description

An unauthenticated path traversal vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to manipulate user generated files, potentially leading to unauthorized changes in critical system configurations, if certain preconditions outside of the attacker's control are met.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hpe networking_fabric_composer *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated path traversal vulnerability in HPE Networking Fabric Composer's API endpoint. It allows an adjacent attacker without authentication to manipulate user-generated files. Exploitation requires certain preconditions outside the attacker's control.

Detection Guidance

Detection of this vulnerability requires checking for unauthorized file manipulation in HPE Networking Fabric Composer's API endpoint. Monitor logs for unusual file access patterns or requests containing path traversal sequences like '../'. Inspect system files for unexpected changes in critical configurations.

Impact Analysis

If exploited, this vulnerability could lead to unauthorized changes in critical system configurations. This may disrupt network operations or cause security misconfigurations, though exploitation depends on specific preconditions.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized changes to critical system configurations through manipulated user-generated files. Unauthorized access or modifications to sensitive data or system settings may violate data protection and privacy requirements under these regulations.

Mitigation Strategies

Apply patches or updates provided by HPE for the Networking Fabric Composer API endpoint. Restrict network access to the API endpoint to trusted sources only. Monitor system configurations for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73737. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart