Executive brief
HPE Networking Fabric Composer is a network management platform used to configure and manage fabric switches and infrastructure. A vulnerability in its underlying operating system allows an unauthenticated attacker on an adjacent network to bypass authentication controls and gain administrative access, enabling them to modify configurations, disrupt network operations, and access sensitive data.
Technical details
The vulnerability is an authentication bypass in the underlying operating system of HPE Networking Fabric Composer. It allows an unauthenticated adjacent network actor to circumvent existing authentication controls without requiring valid credentials. Successful exploitation grants administrative access, enabling attackers to modify system configurations, access or manipulate sensitive data, and potentially compromise the entire fabric management infrastructure. The attack requires network adjacency but no user interaction or prior authentication. Patches are available from HPE.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed