Description
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Published: 2026-09-01
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Web‑Based Management Interface of HPE Networking Fabric Composer. It permits an unauthenticated adjacent attacker to embed malicious script that is stored and later presented to legitimate users. This stored XSS can allow arbitrary JavaScript execution in the victim’s browser within the context of the affected interface, enabling data theft, session hijacking, or further compromise of the management console.

Affected Systems

Affected products include Hewlett Packard Enterprise Fabric Composer. Precise version information is not specified in the advisory. Administrators should verify that they are running a current release and consult the HPE support site for any published patches.

Risk and Exploitability

The CVSS score of 8.8 indicates a high‑severity flaw. The EPSS score is not available, so the exploitation probability cannot be quantified, but the flaw remains unmitigated in existing deployments. It is not listed in CISA’s KEV catalog. The attack can be carried out by sending malicious input that is stored by the management interface and later served to any authenticated user who views the affected page. Because the attack requires no authentication but relies on an adjacent network presence, the threat remains significant for operators of shared management network segments.

Generated by OpenCVE AI on September 2, 2026 at 01:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE Fabric Composer patch that fixes the stored XSS vulnerability.
  • Validate and encode all user‑supplied input that is persisted and displayed by the web interface to prevent script execution.
  • Deploy a Content Security Policy that disallows inline scripts and limits trusted script sources to reduce the impact of any remaining XSS content.

Generated by OpenCVE AI on September 2, 2026 at 01:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Title Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:18.240Z

Reserved: 2026-08-13T16:35:39.126Z

Link: CVE-2026-73703

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T20:17:17.663

Modified: 2026-09-01T21:08:28.570

Link: CVE-2026-73703

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T01:30:20Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')