Executive brief
HPE Networking Fabric Composer is a management platform for network fabric infrastructure. A flaw in its API allows authenticated users with low-level operator permissions to bypass authorization controls and access sensitive information or make changes they should not be permitted to perform, potentially exposing network configuration details or enabling unauthorized modifications.
Technical details
The vulnerability is a privilege escalation flaw in the API of HPE Networking Fabric Composer that fails to properly enforce authorization controls for certain operations. An authenticated user with low-privilege operator role can access information and perform actions beyond their authorized privilege level. The attack requires valid authentication credentials; no unauthenticated network attack is possible. Successful exploitation allows an attacker to retrieve restricted information and make limited unauthorized changes. HPE has released a security update to address this issue.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed