Executive brief
HPE Networking Fabric Composer is a network management and orchestration platform used to configure and monitor data center fabrics. A flaw in its API allows authenticated administrators or privileged users to perform insecure file operations that could lead to remote code execution with system privileges, potentially compromising the entire network infrastructure and the systems it manages.
Technical details
The vulnerability exists in the API of HPE Networking Fabric Composer due to insecure file operations that fail to properly validate or sanitize file paths and operations. An authenticated remote attacker with access to the API can exploit these file operation flaws to upload, modify, or execute arbitrary files with elevated privileges. The attack requires prior authentication and network access to the API endpoint. Successful exploitation enables arbitrary command execution with the privileges of the Fabric Composer service, typically a high-privilege account. Patches are available through HPE support channels.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed