Description
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Published: 2026-09-01
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client-side script execution in the Fabric Composer web management interface
Action: Patch
AI Analysis

Impact

The vulnerability is a reflected cross‑site scripting flaw in the web‑based management interface of HPE Networking Fabric Composer. An attacker can embed malicious JavaScript in a request that is reflected back to a victim’s browser. When a user views the crafted page, the browser executes the injected code in the context of Fabric Composer, allowing the attacker to steal session cookies, credentials, or perform other malicious actions on behalf of the user.

Affected Systems

The affected vendor is Hewlett Packard Enterprise, product Fabric Composer. The advisory does not specify firmware or component versions, so all installations of Fabric Composer that expose the web interface remain vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 6.1 signals a medium severity. Exploitation requires no authentication and proceeds over the network via the unstable web endpoint, making it easier for an attacker with any access to the management interface to launch the attack. No EPSS score is available and the vulnerability is not listed in CISA KEV, but the lack of public exploitation does not reduce its risk. Based on the description, the likely attack vector is a crafted HTTP request that injects script into a reflected response, which is then executed by a victim’s browser while using the interface.

Generated by OpenCVE AI on September 2, 2026 at 01:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE Networking Fabric Composer firmware update that fixes the XSS flaw
  • Restrict the web interface to trusted networks or IP ranges through firewall rules
  • Implement a content‑security policy or web application firewall to block reflected scripts and enforce input validation

Generated by OpenCVE AI on September 2, 2026 at 01:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Thu, 03 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Title Unauthenticated Reflected Cross-Site Scripting (XSS) Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-02T18:57:38.467Z

Reserved: 2026-08-13T16:37:26.896Z

Link: CVE-2026-73731

cve-icon Vulnrichment

Updated: 2026-09-02T16:20:13.248Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:20.703

Modified: 2026-09-03T15:12:59.853

Link: CVE-2026-73731

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:44:19Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')