Executive brief
HPE Networking Fabric Composer is a network management tool used to configure and monitor Hewlett Packard Enterprise network infrastructure. An attacker with administrative access to the management interface can retrieve sensitive configuration and credential information in unencrypted form, potentially enabling lateral movement to other network systems managed by the platform.
Technical details
This vulnerability is an information disclosure flaw in the management interface of HPE Networking Fabric Composer. The vulnerability requires administrative privileges to exploit and allows an attacker to access sensitive data (likely configuration details, credentials, or API tokens) transmitted or stored in cleartext. The attack vector is local to the management interface and relies on the attacker already possessing administrative credentials. Retrieved information could be leveraged to compromise downstream network services or gain unauthorized access to resources integrated with the Fabric Composer.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed