CVE-2026-73706
Medium
Elevated severity or exploit probability.
CVSS base
8.6
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
EPSS — probability of exploitation (30 days)
0.3%
20.9th percentile
CISA KEV
Not listed
Weakness / dates
CWE-306
Published 2026-09-01 · modified 2026-09-02
CVSS breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
| Attack Vector | N | Network |
| Attack Complexity | L | Low |
| Privileges Required | N | None |
| User Interaction | N | None |
| Scope | U | Unchanged |
| Confidentiality | L | Low |
| Integrity | H | High |
| Availability | L | Low |
Timeline
- 2026-09-01 — Published (NVD)
- 2026-09-02 — Last modified (NVD)
Description
A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to obtain limited system information and to change the state of certain settings of a vulnerable system. Successful exploitation could allow an attacker to gain insight into internal services and workflows and to make unauthorized changes that may disrupt the normal operation of the affected service.