Executive brief
HPE Networking Fabric Composer is a network management platform used to configure and monitor fabric switches and networking infrastructure. A privilege escalation vulnerability in its API allows authenticated low-privilege operators to gain administrative access, potentially enabling complete control of the network management system and the infrastructure it controls.
Technical details
A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer that allows an authenticated low-privilege operator user to escalate their permissions to administrative level. The vulnerability is reachable via the API and requires valid authentication credentials. Successful exploitation grants an attacker complete administrative control over the system, enabling them to modify network configurations, access sensitive data, and potentially compromise the entire managed infrastructure.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed