Executive brief
HPE Networking Fabric Composer is a network management platform used to configure and monitor fabric switches. A flaw in its API allows authenticated low-privilege users to access sensitive information they should not be authorized to view, potentially enabling them to gather credentials or configuration data that could lead to broader network compromise.
Technical details
The vulnerability is an authorization bypass in the API of HPE Networking Fabric Composer that allows authenticated low-privilege operator users to access data beyond their assigned privilege level. The flaw enables an attacker with valid credentials to retrieve sensitive information that should be restricted to higher-privilege roles. This information disclosure could facilitate further attacks on downstream network services managed by the platform. Authentication is required to exploit this vulnerability, limiting the attack surface to users with valid accounts.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed