Information Disclosure in HPE Networking Fabric Composer
CVE-2026-73729

6.5MEDIUM

Key Information:

Vendor

HP (HP)

Vendor
CVE Published:
1 September 2026

What is CVE-2026-73729?

A vulnerability exists in HPE Networking Fabric Composer that enables an authenticated user with limited privileges and local access to view sensitive information contained in upstream AFC dependencies. This flaw could potentially allow an attacker to gain visibility into data that surpasses their current access permissions, paving the way for further unauthorized access and exploitation.

Affected Version(s)

Fabric Composer 7.0.0 <= 7.3.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Unknown contributor
.