Hewlett Packard EnterpriseCVE-2026-73706
Hewlett Packard Enterprise Fabric Composer: missing authentication
High8.6CVE-2026-73706 · Published Sep 1, 2026 · updated Sep 2, 2026
A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to obtain limited system information and to change the state of certain settings of a vulnerable system. Successful exploitation could allow an attacker to gain insight into internal services and workflows and to make unauthorized changes that may disrupt the normal operation of the affected service.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Fabric Composer Product | >= 7.0.0, <= 7.3.3 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-306
More Hewlett Packard Enterprise advisories
All Hewlett Packard Enterprise| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 1 | Hewlett Packard Enterprise AOS-CX: remote code execution | High8.8 | No fix yet |
| Sep 1 | Hewlett Packard Enterprise AOS-CX: denial of service | Medium4.9 | No fix yet |
| Sep 1 | Hewlett Packard Enterprise AOS-CX: denial of service | High7.5 | No fix yet |
| Sep 1 | Hewlett Packard Enterprise AOS-CX: buffer overflow | High7.6 | No fix yet |
| Sep 1 | Hewlett Packard Enterprise AOS-CX: information disclosure | High7.7 | No fix yet |
| Sep 1 | Hewlett Packard Enterprise AOS-CX: code execution | High7.9 | No fix yet |