Home

Description

A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affected directory.

PUBLISHED Reserved 2026-01-14 | Published 2026-01-27 | Updated 2026-01-27 | Assigner hpe




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Product status

Default status
affected

7.0.0 (semver)
affected

Credits

Daniel Jensen (@dozernz) reporter

References

support.hpe.com/...y?docId=hpesbnw04996en_us&docLocale=en_US

cve.org (CVE-2026-23593)

nvd.nist.gov (CVE-2026-23593)

Download JSON