CVE-2026-73745
Awaiting Analysis Awaiting Analysis - Queue

Unauthenticated Information Disclosure in HPE Networking Fabric Composer

Vulnerability report for CVE-2026-73745, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Hewlett Packard Enterprise (HPE)

Description

A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some information handled by the affected system. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of unauthorized access when combined with other vulnerabilities.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hpe networking_fabric_composer *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in HPE Networking Fabric Composer's API endpoint allows unauthenticated remote attackers to view some information handled by the system. Exploitation could reveal internal services and workflows, potentially aiding further unauthorized access if combined with other vulnerabilities.

Detection Guidance

This vulnerability may allow unauthenticated remote access to view internal system information. To detect it, monitor network traffic for unauthorized API requests to HPE Networking Fabric Composer endpoints. Check logs for unusual access patterns or requests to the affected API. Use network scanning tools like nmap to identify exposed API endpoints. Example command: nmap -sV --script=http-api-discovery <target_IP>.

Impact Analysis

An attacker could gain insight into internal operations, increasing the risk of unauthorized access. This may lead to data breaches or enable additional attacks if other vulnerabilities are exploited.

Compliance Impact

This vulnerability may expose internal system information, which could potentially lead to unauthorized access if combined with other vulnerabilities. This could impact compliance with standards like GDPR or HIPAA by increasing the risk of data breaches or unauthorized data exposure, though specific compliance impacts depend on the system's configuration and data handling practices.

Mitigation Strategies

Apply patches or updates provided by HPE for Networking Fabric Composer to address the API endpoint vulnerability. Restrict network access to the API endpoint if possible and monitor for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73745. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart