CVE-2026-73741
Awaiting Analysis Awaiting Analysis - Queue

Authenticated File Read Vulnerability in HPE Networking Fabric Composer

Vulnerability report for CVE-2026-73741, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Hewlett Packard Enterprise (HPE)

Description

A vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to view some system files. Successful exploitation could allow an attacker to access limited data beyond what is authorized by the user's existing privilege level.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hpe networking_fabric_composer *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in HPE Networking Fabric Composer's API allows an authenticated low privilege operator user to view some system files. It does not require high privileges or complex conditions to exploit, as the attack vector is network-based with low complexity.

Impact Analysis

An attacker could access limited data beyond the authorized privilege level of a low privilege operator user. This may lead to unauthorized information disclosure, though the impact is constrained by the existing user permissions.

Compliance Impact

This vulnerability allows an authenticated low privilege user to view some system files, potentially exposing limited unauthorized data. This could impact compliance with GDPR by risking unauthorized access to personal data and HIPAA by potentially exposing protected health information if such data is stored in the affected system.

Mitigation Strategies

Update HPE Networking Fabric Composer to the latest patched version to address the file access vulnerability. Ensure all operator users have the least privilege necessary and review user access levels to prevent unauthorized data exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73741. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart