Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arubanetworks
Arubanetworks fabric Composer |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Arubanetworks
Arubanetworks fabric Composer |
Wed, 02 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform, including changes to the configuration of systems managed by the affected product. | |
| Title | Authenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric Composer API | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2026-09-01T20:24:21.378Z
Reserved: 2026-08-13T16:35:39.127Z
Link: CVE-2026-73707
No data.
Status : Analyzed
Published: 2026-09-01T20:17:18.087
Modified: 2026-09-02T13:37:33.527
Link: CVE-2026-73707
No data.
OpenCVE Enrichment
Updated: 2026-09-02T02:15:12Z