Sceawere

Vulnerability Detail

CVE-2026-73745UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

HPE Networking Fabric Composer Information Disclosure

Vulnerability Metadata

Severity
Low
Score / CVSS
3.1
Creation Date
2h ago
Vendor
Hewlett Packard Enterprise (HPE)
Product
Fabric Composer
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some information handled by the affected system. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of unauthorized access when combined with other vulnerabilities.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.1",
  "pubDate": "2026-09-01T20:17:22.217Z",
  "pubdate": "2026-09-01T20:17:22.217Z",
  "executiveSummary": "A vulnerability exists within the API endpoint of HPE Networking Fabric Composer, classified as an unauthenticated information disclosure flaw.\nThis vulnerability allows remote, unauthenticated attackers to retrieve sensitive system-handled data, including details regarding internal services and workflow configurations.\nThe primary risk involves the exposure of infrastructure metadata, which can be leveraged as a reconnaissance phase to orchestrate further attacks.\nBy gaining insight into the internal architecture and service landscape, an attacker can map the environment to identify secondary vulnerabilities, potentially facilitating unauthorized system access.\nExploitation requires network access to the target's API endpoint and does not necessitate prior authentication or elevated privileges, making it a significant concern for internal network security posture.",
  "technicalDetails": "The vulnerability resides within the API implementation of HPE Networking Fabric Composer, which fails to correctly enforce authentication controls for specific endpoints. This failure manifests as an Information Disclosure vulnerability, where the application processes requests from unauthenticated clients that should otherwise be restricted to authorized users or service accounts.\nThe root cause is identified as an improper access control implementation within the API gateway layer or the underlying application logic governing resource requests. When an unauthenticated HTTP request is sent to the vulnerable API endpoint, the system responds with sensitive system information rather than a 401 Unauthorized or 403 Forbidden response. This indicates that the endpoint lacks the necessary middleware or validation logic to verify the session identity before retrieving or processing internal metadata.\nThe attack flow begins with the reconnaissance phase, where an attacker scans the network to identify the HPE Networking Fabric Composer API interface. Once identified, the attacker crafts specific GET or POST requests directed at the vulnerable endpoint. Because the application logic fails to validate the request origin or session tokens, the backend processes the request and returns serialized data structures—such as JSON or XML—containing internal configuration details, service status indicators, and workflow identifiers.\nThe impact of this disclosure is critical in the context of reconnaissance. Exposure of internal services and workflows reveals architectural details such as service dependencies, internal naming conventions, and potentially the configuration logic used for network orchestration. An attacker can correlate this information to identify vulnerable downstream components or misconfigured integrations that may be present within the fabric environment. By aggregating this information, an attacker can move laterally or chain this disclosure with other existing vulnerabilities to escalate privileges or bypass secondary security controls, thereby compromising the integrity and confidentiality of the HPE Networking Fabric Composer managed environment."
}
CVE-2026-73745: HPE Networking Fabric Composer Information Disclosure (LOW Severity, CVSS: 3.1) - Sceawere