Executive brief
HPE Networking Fabric Composer is a network fabric management platform used to administer and control enterprise networking infrastructure. The product's API contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain administrative access, leading to complete compromise of the Fabric Composer system and potentially the entire managed network fabric.
Technical details
An authentication bypass vulnerability exists in the API of HPE Networking Fabric Composer, allowing unauthenticated remote attackers to circumvent authentication controls. The vulnerability is accessible over the network without requiring prior authentication or user interaction. Successful exploitation grants an attacker administrative privileges, enabling full compromise of the affected host and potentially the managed infrastructure it controls. This is a pre-authentication remote code execution pathway that presents critical risk to network environments relying on this management platform.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed