Executive brief
HPE Networking Fabric Composer is a network management platform used to orchestrate fabric configurations across HPE networking infrastructure. An unauthenticated remote attacker can exploit a vulnerability in the underlying operating system to execute arbitrary code with privileged access, completely compromising the management host and potentially the entire managed network infrastructure.
Technical details
An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. The vulnerability allows an unauthenticated remote attacker to execute arbitrary code with privileged user permissions on the underlying operating system. Successful exploitation requires certain preconditions to be met that are outside of the attacker's direct control. An exploit would result in complete compromise of the affected Fabric Composer host, potentially enabling lateral movement and control of managed networking resources.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed