CVE-2026-76657 PUBLISHED

Authentication Bypass in HPE Networking Fabric Composer API allows Administrative Access

Assigner: hpe
Reserved: 19.08.2026 Published: 01.09.2026 Updated: 01.09.2026

Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 10

Product Status

Vendor Hewlett Packard Enterprise (HPE)
Product Fabric Composer
Versions Default: affected
  • affected from 7.0.0 to 7.3.3 (incl.)

Credits

  • This vulnerability was discovered by internal security research at HPE Networking. reporter

References