Sceawere

Vulnerability Detail

CVE-2026-73721UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

HPE Networking Fabric Composer SQLi

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
2h ago
Vendor
Hewlett Packard Enterprise (HPE)
Product
Fabric Composer
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to conduct SQL injection attacks against the HPE Networking Fabric Composer instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the HPE Networking Fabric Composer host.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-09-01T20:17:19.620Z",
  "pubdate": "2026-09-01T20:17:19.620Z",
  "executiveSummary": "HPE Networking Fabric Composer contains vulnerabilities in its API component that enable SQL injection (SQLi) attacks. These flaws originate from improper neutralization of user-supplied data before incorporating it into database queries. Successful exploitation allows an authenticated remote attacker to execute arbitrary SQL commands against the underlying database instance. This capability poses a severe security risk, as it grants unauthorized access to sensitive information, enables data modification, and may facilitate complete system compromise of the host environment. The vulnerability requires the attacker to possess valid authentication credentials to the affected API, but does not require physical access to the server, making it a significant concern for environments where internal network segments or management interfaces are accessible to potentially malicious actors.",
  "technicalDetails": "The vulnerability resides within the API endpoints of HPE Networking Fabric Composer, which fails to adequately sanitize or parameterize input prior to processing database operations. SQL injection occurs when an attacker crafts malicious input to manipulate the structure of the intended SQL query. By injecting meta-characters or SQL syntax into API requests, the attacker can break out of the intended data context and append arbitrary logic to the query execution flow.\nThe attack flow begins with the adversary authenticating to the HPE Networking Fabric Composer API. Upon gaining access, the attacker identifies API parameters susceptible to injection. By substituting standard input with crafted SQL fragments—such as UNION-based payloads or boolean-based inference techniques—the attacker forces the database engine to execute unauthorized instructions. Because the API process interacts with the database with elevated privileges, the execution context is frequently sufficient to permit full administrative manipulation of the schema.\nPost-exploitation impact is extensive. Since the application database likely contains sensitive configuration metadata, system logs, and potentially stored credentials for broader network fabric management, an attacker can extract this information to facilitate lateral movement or persistence. Furthermore, if the database configuration permits, the attacker might leverage specialized SQL commands (such as 'xp_cmdshell' in MSSQL or equivalent procedural execution functions in other engines) to break out of the database context and execute arbitrary shell commands on the underlying host operating system. This results in complete compromise of the HPE Networking Fabric Composer instance, potentially allowing the attacker to intercept or modify fabric management traffic, reconfigure network policies, or disable security monitoring features.\nThe vulnerability is limited to the API interface, requiring an authenticated session, which constrains the attack surface to legitimate users or compromised accounts. However, in the context of administrative infrastructure, the privilege level afforded by such an account is typically high, exacerbating the overall risk score and the potential for full-scale environment disruption."
}
CVE-2026-73721: HPE Networking Fabric Composer SQLi (HIGH Severity, CVSS: 7.2) - Sceawere