CVE-2026-73737: Unauthenticated Path Traversal in HPE Networking Fabric Composer API Endpoint Allows Unauthorized File Modification
An unauthenticated path traversal vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to manipulate user generated files, potentially leading to unauthorized changes in critical system configurations, if certain preconditions outside of the attacker's control are met.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require an account or user interaction?
No privileges are required, but exploitation requires user interaction. The attack is limited to an adjacent attacker and has high attack complexity, with additional preconditions outside the attacker’s control.
Is this expected to expose data or cause a service outage?
The supplied impact vector indicates no confidentiality or availability impact. The primary impact is high integrity impact through unauthorized modification of user-generated files, potentially affecting critical system configurations.