Executive brief
HPE Networking Fabric Composer is a network management platform used to configure and administer fabric switches and networking infrastructure. A vulnerability in its API allows unauthenticated attackers to execute arbitrary commands on the underlying host system, potentially compromising the entire management platform and all connected network devices.
Technical details
The vulnerability exists in the API of HPE Networking Fabric Composer and allows remote code execution via an unauthenticated attack vector. The flaw permits an attacker to execute arbitrary commands on the underlying operating system with the privileges of the Fabric Composer service. While the vulnerability requires certain preconditions outside the attacker's control to be met, successful exploitation results in complete system compromise. No authentication is required to trigger the vulnerability.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed