Executive brief
HPE Networking Fabric Composer is a management platform for network fabric infrastructure. An unauthenticated attacker can access sensitive information through an exposed API endpoint, potentially revealing details about internal services and configurations that could be leveraged in follow-up attacks.
Technical details
A vulnerability in an API endpoint of HPE Networking Fabric Composer allows unauthenticated remote access to sensitive information. The issue stems from insufficient access controls on the affected endpoint, allowing attackers to enumerate internal services and workflows without authentication. The vulnerability is network-reachable and requires no user interaction or valid credentials. Successful exploitation grants visibility into system architecture and services, which can facilitate reconnaissance for subsequent targeted attacks. The vendor has released patches to restrict API endpoint access.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed