Executive brief
HPE Networking Fabric Composer is a management platform for network fabric systems. A flaw in its API allows authenticated operators with limited privileges to access files beyond their authorized access level, potentially exposing sensitive system data to unauthorized viewing.
Technical details
The vulnerability exists in the API of HPE Networking Fabric Composer and permits privilege escalation through improper access control. An authenticated user with low-privilege operator credentials can bypass authorization checks to read arbitrary system files. The attack requires valid authentication credentials but does not require administrative privileges or user interaction. Successful exploitation results in information disclosure of data that should be restricted to higher privilege levels. Patches are available from HPE.
Affected products
- HPE Networking Fabric Composer <UNKNOWN>
Timeline
- 2026-09-01: disclosed