CVE-2026-73729: Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer
A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to upstream AFC dependencies to view sensitive information. Successful exploitation could allow an attacker to access data beyond what is authorized by the user's existing privilege level, potentially leading to further unauthorized access.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
The issue affects authenticated low-privilege operator users who have local access to upstream AFC dependencies. It is not described as exploitable by unauthenticated or purely remote attackers.
What could an attacker gain through exploitation?
An attacker could view sensitive information and access data beyond the authorization granted by their existing privilege level. The disclosure could potentially support further unauthorized access.
What access does an attacker need before exploiting this vulnerability?
The attacker must already be authenticated as a low-privilege operator user and have local access to upstream AFC dependencies.