CVE-2026-73726: Authentication Bypass in HPE Networking Fabric Composer allows Unauthorized Administrative Access
A vulnerability has been identified in the underlying operating system of HPE Networking Fabric Composer that could potentially allow an unauthenticated adjacent actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative access, modify system configurations, and access or manipulate sensitive data.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
HPE Networking Fabric Composer deployments are exposed where an attacker can act from an adjacent network position. The provided information does not indicate that internet-only reachability is sufficient.
What does an attacker need to exploit it?
The attacker does not need prior privileges or user interaction, but exploitation has high attack complexity and requires adjacent-network access. Successful exploitation can bypass authentication controls and obtain administrative access.
What could an attacker do after successful exploitation?
An attacker could modify system configurations and access or manipulate sensitive data. The listed impact includes high confidentiality and integrity impact, with no availability impact indicated.