CVE-2026-73733: Authentication Bypasses in API allow Continued Authenticated Access in HPE Networking Fabric Composer
Published Sep 1, 2026
·Updated
Authentication bypasses in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to circumvent existing authentication controls. Successful exploitation could allow an attacker to retain limited access to the affected system after that access should have been revoked.
Affected Software
2 affected components
HPE HPE Networking Fabric Composer
Arubanetworks Fabric Composer<=7.3.3
Event History
Sep 1, 2026
CVE Published
via MITRE·07:47 PM
Data Sourced
via MITRE·07:47 PM
DescriptionSeverity
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What access must an attacker have before attempting exploitation?
The attacker must already be authenticated as a low-privilege operator user. No user interaction is required.
2
What is the practical impact of successful exploitation?
An attacker could retain limited access to the affected system after that access should have been revoked. The reported impact is limited confidentiality and integrity impact, with no availability impact.