Executive brief
HPE Networking Fabric Composer is a network management platform used to configure and monitor fabric switches. Authenticated attackers can inject malicious SQL commands through the API to read, modify, or delete sensitive database information, potentially compromising the entire management system and the network infrastructure it controls.
Technical details
The vulnerability is a SQL injection flaw in the API endpoints of HPE Networking Fabric Composer. An authenticated attacker can craft malicious SQL queries in API requests to manipulate database operations. The attack requires valid credentials to access the API, but once authenticated, an attacker can extract sensitive data, modify configurations, or corrupt the database, potentially leading to complete compromise of the management host. Patches are available from HPE support.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed