Executive brief
HPE Networking Fabric Composer is a network management platform used to operate and configure fabric-based data center networks. A flaw in its API allows low-privilege users to bypass authentication controls and retain access to the system even after their credentials should have been revoked, potentially enabling unauthorized management of critical network infrastructure.
Technical details
The vulnerability is an authentication bypass in the API of HPE Networking Fabric Composer that allows an authenticated, low-privilege operator user to circumvent existing authentication controls. The attack requires prior authentication (the attacker must already have valid credentials), and successful exploitation enables an attacker to maintain access to the affected system after legitimate access should have been revoked. The specific mechanism of the bypass is not detailed in the available reference material, but the impact is limited to retaining access rather than escalating privileges.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed