CVE-2026-73706: Authentication Bypass in the API of HPE Networking Fabric Composer allows Data Exposure and Unauthorized Changes
A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to obtain limited system information and to change the state of certain settings of a vulnerable system. Successful exploitation could allow an attacker to gain insight into internal services and workflows and to make unauthorized changes that may disrupt the normal operation of the affected service.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue can be exploited remotely over the network without authentication or user interaction. The attack complexity is rated low.
What could an attacker do after successful exploitation?
An attacker could obtain limited system information, gain insight into internal services and workflows, and change the state of certain settings. Unauthorized changes may disrupt normal operation of the affected service.