Executive brief
HPE Networking Fabric Composer is a management platform for enterprise network infrastructure. An authenticated administrator can exploit an arbitrary file write flaw to escalate privileges and execute commands with root access on the underlying system, potentially compromising the entire network fabric.
Technical details
The vulnerability is an arbitrary file write flaw in the API of HPE Networking Fabric Composer that allows authenticated administrative users to write arbitrary files on the system. The root cause lies in insufficient validation of file paths in API endpoints. Attack requires valid administrative credentials and direct network access to the API. Successful exploitation enables remote code execution with root privileges on the underlying operating system. HPE has released patches; affected versions should be updated immediately.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed