← back
CVE-2026-73706highCWE-306

Authentication Bypass in the API of HPE Networking Fabric Composer allows Data Exposure and Unauthorized Changes

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.6epss 0.5%
exploitation probability
0.5%top 63% of all CVEs
observed exploitation
nono source reports it
A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to obtain limited system information and to change the state of certain settings of a vulnerable system. Successful exploitation could allow an attacker to gain insight into internal services and workflows and to make unauthorized changes that may disrupt the normal operation of the affected service.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L