CVE-2026-73742: Improper Client Address Validation allows Request Attribution Spoofing in Fabric Composer API Endpoint
Published Sep 1, 2026
·Updated
A vulnerability in an API endpoint of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to spoof the source address attributed to their requests. Successful exploitation could allow an attacker to cause inaccurate attribution information to be recorded on the affected system.
Event History
Sep 1, 2026
CVE Published
via MITRE·07:47 PM
Data Sourced
via MITRE·07:47 PM
DescriptionSeverity
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be authenticated to the Fabric Composer API endpoint as a low-privilege operator user. No user interaction is required.
2
What is the practical impact of exploitation?
The attacker can spoof the source address attributed to their requests, causing inaccurate attribution information to be recorded on the affected system. The provided severity vector indicates integrity impact only, with no stated confidentiality or availability impact.