Executive brief
HPE Networking Fabric Composer is a web-based management tool for network fabric infrastructure. A vulnerability allows an unauthenticated attacker to perform unauthorized actions or retrieve sensitive information by tricking an authenticated administrator into visiting a malicious link. An exploit could expose network configuration details or enable lateral movement within managed network infrastructure.
Technical details
This is a cross-site request forgery (CSRF) vulnerability in the web-based management interface of HPE Networking Fabric Composer. The vulnerability requires user interaction—specifically, an attacker must trick an authenticated user into clicking a specially crafted URL. The attack is unauthenticated from the attacker's perspective because the malicious request leverages the victim's existing authenticated session. Successful exploitation allows retrieval of sensitive information that could facilitate further attacks on network services. The vulnerability is network-accessible and requires no special privileges, only social engineering to trick an authenticated user.
Affected products
- HPE Networking Fabric Composer <UNKNOWN>
Timeline
- 2026-09-01: disclosed