Executive brief
HPE Networking Fabric Composer is a network fabric management platform used to configure and monitor enterprise network infrastructure. A vulnerability in its underlying operating system could allow an authenticated low-privilege operator with local access to view sensitive information beyond their authorization level, potentially enabling further unauthorized access to network configuration and data.
Technical details
This vulnerability exists in the underlying operating system layer of HPE Networking Fabric Composer. An authenticated low-privilege operator user with local access to upstream AFC (Automation Framework Components) dependencies can exploit insufficient privilege isolation to read sensitive information and data that should be restricted to higher-privilege users. The attack requires prior authentication and local system access. Successful exploitation allows privilege escalation to access unauthorized data, which could serve as a pivot point for further attacks on the network fabric infrastructure. HPE has released security guidance (hpesbnw05133en_us) addressing this vulnerability.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed