CVE-2026-73700
Awaiting Analysis Awaiting Analysis - Queue

Stored XSS in HPE Networking Fabric Composer Web Interface

Vulnerability report for CVE-2026-73700, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Hewlett Packard Enterprise (HPE)

Description

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hpe networking_fabric_composer *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in HPE Networking Fabric Composer's web-based management interface. An authenticated low-privilege operator user can inject malicious scripts that are stored on the server and executed when an administrative user views the affected interface.

Detection Guidance

Detecting this vulnerability requires checking for stored XSS in the HPE Networking Fabric Composer web interface. Inspect browser console logs for suspicious scripts, review user input fields for unusual payloads, and monitor network traffic for unauthorized script execution. No specific commands are provided in the available resources.

Impact Analysis

An attacker could steal session cookies, perform actions as the admin user, or redirect the admin to malicious sites. This could lead to unauthorized access, data theft, or further compromise of the network management system.

Compliance Impact

This vulnerability could violate compliance requirements by allowing unauthorized access to sensitive data or administrative functions. GDPR may require breach notification, while HIPAA could consider this an unauthorized disclosure of protected health information.

Mitigation Strategies

Apply the latest security patches from HPE as soon as they are available. Restrict access to the web-based management interface to trusted users only. Monitor administrative user sessions for unusual activity. Review and sanitize all user inputs to prevent XSS attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73700. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart