Executive brief
HPE Networking Fabric Composer is a network fabric management platform. A flaw in its API allows authenticated low-privilege operators to escalate their access and modify network settings beyond their authorization level, potentially allowing unauthorized changes to critical network infrastructure.
Technical details
A business logic vulnerability exists in the API of HPE Networking Fabric Composer that allows privilege escalation. The vulnerability can be exploited by an authenticated low-privilege user to gain elevated privileges and modify settings that should be restricted by their current access level. The attack requires valid authentication credentials but allows an operator to exceed their authorized scope. No patch status is explicitly confirmed in the provided advisory text.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed