CVE-2026-73727: Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer API
Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to access sensitive information. A successful exploit allows an attacker to access data beyond what is authorized by the user's existing privilege level, which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need?
The attacker needs an authenticated low-privilege operator account. No user interaction is required.
What is the practical impact of successful exploitation?
An attacker could access sensitive data beyond their authorized privilege level. That information could potentially be used to gain further access to network services supported by HPE Networking Fabric Composer.
Is this an availability or integrity issue?
The provided severity vector indicates high confidentiality impact, with no integrity or availability impact.