Executive brief
HPE Networking Fabric Composer is a network management platform used to configure and monitor fabric-based data center networks. A vulnerability in its API allows authenticated operators to view sensitive data and configuration details beyond their assigned permission level, potentially enabling lateral movement and unauthorized access to network infrastructure.
Technical details
The vulnerability is an information disclosure flaw in the API of HPE Networking Fabric Composer that affects privilege boundary enforcement. An authenticated user with low-privilege operator credentials can bypass authorization checks to access data reserved for higher-privilege accounts. The attack requires valid API authentication; no network-level access controls are bypassed. Successful exploitation allows an attacker to enumerate sensitive configuration, credentials, or operational data that could facilitate further attacks on the fabric infrastructure. HPE has released patches; check support portal hpesbnw05133en_us for details.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed