VDB

GCVE-110-NCSC-2026-339

GCVE-110-NCSC-2026-339
Advisory PublishedCVSS 2.5/10
Vulnetix · Advisory published September 3, 2026
A vulnerability in the HPE Networking Fabric Composer API allows unauthenticated remote attackers to bypass authentication and gain administrative access, potentially compromising the entire host system.

Weaknesses (CWE)

CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-94Improper Control of Generation of Code ('Code Injection')CWE-863Incorrect AuthorizationCWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-552Files or Directories Accessible to External PartiesCWE-306Missing Authentication for Critical FunctionCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-352Cross-Site Request Forgery (CSRF)CWE-73External Control of File Name or PathCWE-601URL Redirection to Untrusted Site ('Open Redirect')CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-290Authentication Bypass by Spoofing

Risk Scores

CVSS 3.1
2.5/10
Low · CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
Hewlett Packard Enterprise (HPE)vers:unknown/*
Aruba Networksvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

3,521 records in the GCVE database · Updated September 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›