CVE-2026-73738: Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer
A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to view sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further privileges on the affected system.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
The issue affects deployments of HPE Networking Fabric Composer where a low-privilege operator user has local access to the system. It is not described as remotely exploitable without local access.
What does an attacker need to exploit it?
An attacker needs an authenticated low-privilege operator account and local access. Exploitation also has high attack complexity, according to the provided CVSS vector.
What is the likely impact if exploitation succeeds?
An attacker could view sensitive information on the affected system. That information could potentially be used to obtain further privileges; the provided vector indicates high confidentiality impact and no direct integrity or availability impact.