Executive brief
HPE Networking Fabric Composer is a management and orchestration platform for data center networking infrastructure. A local privilege escalation vulnerability in this product allows an authenticated local attacker to execute arbitrary code with root-level privileges, potentially compromising the entire management infrastructure and all connected network devices.
Technical details
This vulnerability is a local privilege escalation flaw in HPE Networking Fabric Composer that permits authenticated local attackers to achieve arbitrary code execution with root privileges on the underlying operating system. The attack requires local access to the affected system (physical or logical console access). Successful exploitation grants an attacker root-level control over the Fabric Composer instance, enabling complete compromise of the management platform and potentially all network infrastructure it manages. Patch availability should be verified through HPE support channels.
Affected products
- HPE Networking Fabric Composer <UNKNOWN>
Timeline
- 2026-09-01: disclosed