CVE-2026-23593

HIGH

HPE Aruba Networking Fabric Composer - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affected directory.

Scores

CVSS v3 7.5
EPSS 0.0064
EPSS Percentile 45.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
Hewlett Packard Enterprise (HPE)/HPE Aruba Networking Fabric Composer 7.0.0 - 7.2.3
Published Jan 27, 2026
Tracked Since Feb 18, 2026