SQL Injection Vulnerabilities in HPE Networking Fabric Composer
CVE-2026-73721

7.2HIGH

Key Information:

Vendor

HP (HP)

Vendor
CVE Published:
1 September 2026

What is CVE-2026-73721?

Vulnerabilities present in the API of HPE Networking Fabric Composer allow authenticated remote attackers to execute SQL injection attacks. By exploiting these vulnerabilities, attackers may gain unauthorized access to sensitive information stored in the underlying database. This can lead to unauthorized data modification and potential compromise of the host system, significantly affecting the security and integrity of the networking infrastructure.

Affected Version(s)

Fabric Composer 7.0.0 <= 7.3.3

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Unknown contributor
.