CVE-2026-73745: Unauthenticated Limited Information Disclosure allows Data Exposure in the API of HPE Networking Fabric Composer
A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some information handled by the affected system. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of unauthorized access when combined with other vulnerabilities.
Affected Software
Event History
Frequently Asked Questions
Does an attacker need credentials to exploit this issue?
No. The vulnerability is described as exploitable by an unauthenticated remote attacker through an API endpoint.
What conditions make exploitation more difficult?
The CVSS vector rates attack complexity as high and indicates that user interaction is required. The provided information does not specify what interaction is needed.
What information could be exposed?
Successful exploitation could reveal some information handled by the affected system, including insight into internal services and workflows. The disclosure is limited, but it may increase the risk of unauthorized access when combined with other vulnerabilities.