Executive brief
An authenticated user with low privileges can submit specially crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system. This vulnerability allows a low-level administrator or operator to escalate their capabilities and gain full control over the system, potentially compromising sensitive data, disrupting operations, or using the system as a pivot point for further attacks.
Technical details
This vulnerability is a command injection flaw in the web-based management interface accessible to authenticated users. An attacker with low-privileged credentials (such as a read-only user or operator role) can craft malicious input that is not properly sanitized before being passed to operating system command execution functions. The attack requires valid authentication but no elevated privileges, and can be triggered remotely through the web interface. Successful exploitation allows arbitrary command execution with the privileges of the management service, potentially leading to full system compromise. A patch is expected from HPE as indicated by the support advisory reference.
Affected products
- HPE <UNKNOWN>
Timeline
- 2026-09-01: disclosed