Executive brief
HPE Networking Fabric Composer is a network management platform used to orchestrate fabric infrastructure. A denial-of-service vulnerability in its API allows authenticated operators with low-level privileges to crash or disable the service, disrupting network management operations and potentially affecting business-critical network infrastructure availability.
Technical details
Denial-of-service vulnerabilities exist in the API of HPE Networking Fabric Composer. The vulnerability requires authentication as a low-privilege operator user. An attacker with valid low-privilege credentials can craft specific API requests that cause the service to become unavailable, interrupting normal operation of the affected platform. No remote unauthenticated exploitation is possible. Patches are available from HPE.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed