Executive brief
HPE Networking Fabric Composer is a network management and orchestration platform used to configure and monitor fabric-based networking environments. An authenticated operator user can exploit a file write flaw in the API to escalate privileges and execute arbitrary commands, potentially compromising the entire management platform and all connected network infrastructure.
Technical details
The vulnerability is an arbitrary file write flaw in the API of HPE Networking Fabric Composer that allows privilege escalation. An authenticated low-privilege operator user can write arbitrary files through the API, enabling them to escalate to higher privileges and execute arbitrary commands on the underlying operating system. The attack requires valid authentication credentials but no elevated initial privileges. Successful exploitation results in complete system compromise with OS-level command execution.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed