Description
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Published: 2026-09-01
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary client‑side script execution in the Fabric Composer web interface
Action: Patch When Available
AI Analysis

Impact

A stored cross‑site scripting flaw in the HPE Networking Fabric Composer management interface lets a logged‑in low‑privilege operator inject malicious script that is saved and later rendered for any administrative user. On execution, the script runs with the victim administrator’s privileges in the browser, enabling data theft, session hijacking, or redirection attacks. The vulnerability does not directly compromise the underlying server, but it can provide attackers a foothold for broader compromises if an administrator’s session is hijacked.

Affected Systems

The affected product is Hewlett Packard Enterprise’s Fabric Composer web‑based management subsystem. No specific firmware or software version ranges are listed in the available data, so all releases of the interface that allow the operator to submit forged input are presumed vulnerable until verified by HPE.

Risk and Exploitability

The CVSS score of 9 indicates a high‑severity vulnerability with high impact. EPSS data is not available, and the issue is not currently listed in the CISA KEV catalog, implying limited evidence of exploitation at this time. However, based on the description, it is inferred that the attack vector is an authenticated low‑privilege operator who submits malicious input through the Fabric Composer web interface. This makes the attack path likely for insiders or compromised accounts. The exploit path involves injecting malicious HTML/JavaScript through form fields or data entries that are later displayed to administrators, so while the probability of exploitation is uncertain, the potential damage warrants prompt remediation.

Generated by OpenCVE AI on September 2, 2026 at 02:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Fabric Composer to the latest firmware or patch version that fixes the stored XSS flaw.
  • If a patch is not yet available, restrain low‑privilege operator access or disable the functionality that accepts user‑supplied data which is rendered to administrators.
  • Apply a web application firewall rule or browser security policy to block execution of any injected script on the Fabric Composer interface.
  • Monitor system logs for anomalous script activity or unexpected changes in the web interface content.

Generated by OpenCVE AI on September 2, 2026 at 02:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Title Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in HPE Networking Fabric Composer Web-Based Management Interface
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T15:11:33.373Z

Reserved: 2026-08-13T16:35:39.126Z

Link: CVE-2026-73700

cve-icon Vulnrichment

Updated: 2026-09-02T15:11:19.751Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:17.343

Modified: 2026-09-02T16:26:31.183

Link: CVE-2026-73700

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T21:39:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')