Executive brief
HPE Networking Fabric Composer is a network management platform that controls fabric switches and infrastructure. An authentication bypass vulnerability in its underlying operating system allows unauthenticated attackers on the same network segment to execute code with system privileges, potentially gaining complete control of the management host and all connected network equipment.
Technical details
This is an authentication bypass vulnerability in the underlying operating system of HPE Networking Fabric Composer. An unauthenticated adjacent attacker can exploit this flaw to achieve arbitrary code execution with privileged user rights on the OS layer. The attack vector is adjacent network access (same network segment), requiring no prior authentication. Successful exploitation results in complete compromise of the AFC host, including potential control over managed fabric infrastructure. Patches are expected to be available through HPE security advisories.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed: CVE-2026-19766 published