Sceawere
Vulnerability Detail
CVE-2026-73739UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
HPE Fabric Composer Information Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.4
- Creation Date
- 2h ago
- Vendor
- Hewlett Packard Enterprise (HPE)
- Product
- Fabric Composer
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability exists in the API of HPE Networking Fabric Composer that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve sensitive information that was expected to remain protected within the affected system.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.4",
"pubDate": "2026-09-01T20:17:21.530Z",
"pubdate": "2026-09-01T20:17:21.530Z",
"executiveSummary": "A sensitive information disclosure vulnerability exists within the API of HPE Networking Fabric Composer. This vulnerability allows an authenticated attacker with administrative privileges to retrieve data that should remain protected. The issue stems from the improper handling of sensitive information, resulting in the exposure of data in cleartext format. This represents a critical security oversight in the system's data protection architecture. The impact of successful exploitation includes the unauthorized access to sensitive system information, potentially leading to further compromise of the environment. The vulnerability requires administrative-level access, meaning an attacker must already possess elevated privileges within the management plane to initiate an exploit. The risk implications are significant, as cleartext exposure of sensitive configuration or operational data can compromise the integrity and confidentiality of the entire fabric management domain.",
"technicalDetails": "The vulnerability resides within the API implementation of HPE Networking Fabric Composer, specifically involving the processing and transmission of sensitive data objects. The root cause is the failure to enforce secure transport or storage mechanisms for sensitive information, leading to its availability in cleartext within API responses despite the intended protection policies.\nExploitation requires the attacker to possess administrative privileges within the HPE Networking Fabric Composer management interface. The attack flow involves an authenticated user interacting with specific API endpoints that fail to sanitize or encrypt sensitive data payloads before delivery to the client. By sending crafted, authenticated HTTP requests to the vulnerable API methods, an attacker can trigger the retrieval of data that is erroneously returned in plaintext. Because the system lacks proper field-level authorization or response masking, the API serves as a conduit for exfiltrating internal data that should be obscured.\nThe vulnerable component is the API handler responsible for processing queries regarding sensitive system configurations. When the API executes the backend logic to retrieve these entities, it bypasses security checks that should ensure sensitive fields are redacted or encrypted. Consequently, the API response contains cleartext tokens, credentials, or proprietary fabric configuration details. The exposure is limited to the administrative interface and requires active network connectivity to the Fabric Composer management plane. Post-exploitation impact includes the potential exposure of highly sensitive fabric infrastructure details, service credentials, or topology-specific information which can be leveraged to escalate the compromise or move laterally within the managed network fabric. The lack of cryptographic protection at the application layer during the retrieval process highlights a significant architectural flaw in how the system handles sensitive configuration data internally."
}