CVE-2026-73748: Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer
A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of HPE Networking Fabric Composer are exposed through the affected interface if an attacker already has administrative privileges. The vulnerability does not describe unauthenticated access.
What does an attacker need to exploit it?
An attacker needs network access, administrative privileges, and must successfully navigate a high-complexity attack path. No user interaction is required.
What could an attacker obtain?
The attacker can retrieve sensitive information in cleartext format. That information could potentially be used to gain further access to network services supported by HPE Networking Fabric Composer.