Executive brief
HPE Networking Fabric Composer is a web-based management tool for enterprise network fabric infrastructure. An unauthenticated attacker can read arbitrary files on the system through the management interface, potentially exposing sensitive configuration data, credentials, or system information that could be used for further attacks.
Technical details
This vulnerability is a path traversal/directory traversal flaw in the web-based management interface of HPE Networking Fabric Composer. The vulnerability allows an unauthenticated remote attacker to read arbitrary files within the affected directory by manipulating file path parameters. No authentication is required to exploit this issue, making it remotely exploitable by any network-accessible user. Successful exploitation enables an attacker to access sensitive system files and configuration information. HPE has released patches to address this vulnerability.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed