VDB
GCVE-110-NCSC-2026-339
GCVE-110-NCSC-2026-339
Advisory PublishedCVSS 2.5/10
A vulnerability in the HPE Networking Fabric Composer API allows unauthenticated remote attackers to bypass authentication and gain administrative access, potentially compromising the entire host system.
Weaknesses (CWE)
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-94Improper Control of Generation of Code ('Code Injection')CWE-863Incorrect AuthorizationCWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-552Files or Directories Accessible to External PartiesCWE-306Missing Authentication for Critical FunctionCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-352Cross-Site Request Forgery (CSRF)CWE-73External Control of File Name or PathCWE-601URL Redirection to Untrusted Site ('Open Redirect')CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-290Authentication Bypass by Spoofing
Risk Scores
CVSS 3.1
2.5/10
Low · CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | vers:unknown/* | — | — |
| Aruba Networks | vers:unknown/* | — | — |
Aliases
CVE-2026-19766CVE-2026-73700CVE-2026-73701CVE-2026-73702CVE-2026-73703CVE-2026-73704CVE-2026-73705CVE-2026-73706CVE-2026-73707CVE-2026-73708CVE-2026-73709CVE-2026-73710CVE-2026-73711CVE-2026-73713CVE-2026-73714CVE-2026-73716CVE-2026-73717CVE-2026-73718CVE-2026-73719CVE-2026-73720CVE-2026-73722CVE-2026-73723CVE-2026-73724CVE-2026-73725CVE-2026-73726CVE-2026-73727CVE-2026-73728CVE-2026-73729CVE-2026-73731CVE-2026-73732CVE-2026-73733CVE-2026-73734CVE-2026-73735CVE-2026-73736CVE-2026-73737CVE-2026-73739CVE-2026-73740CVE-2026-73741CVE-2026-73742CVE-2026-73744CVE-2026-73745CVE-2026-73746CVE-2026-73747CVE-2026-76657CVE-2026-76658
References
Browse GCVE Records
3,521 records in the GCVE database · Updated September 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.