CVE-2026-73703
Awaiting Analysis Awaiting Analysis - Queue

Stored XSS in HPE Networking Fabric Composer Web Interface

Vulnerability report for CVE-2026-73703, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Hewlett Packard Enterprise (HPE)

Description

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hpe networking_fabric_composer *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored cross-site scripting (XSS) flaw in the web-based management interface of HPE Networking Fabric Composer. It allows an unauthenticated attacker within the same network to inject malicious scripts that are stored on the server and executed when a user accesses the affected interface.

Detection Guidance

This vulnerability involves a stored XSS attack in HPE Networking Fabric Composer's web interface. Detection requires manual inspection of the web interface for improper input validation in user-supplied data fields. Check for unusual script tags or payloads in stored data like device names, descriptions, or user profiles. No specific commands are provided in the context.

Impact Analysis

An attacker could exploit this to execute arbitrary script code in your browser when you access the HPE Networking Fabric Composer interface. This could lead to session hijacking, data theft, or unauthorized actions performed on your behalf.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Organizations may face compliance violations if exploited.

Mitigation Strategies

Update HPE Networking Fabric Composer to the latest patched version to address the stored XSS vulnerability. Restrict access to the web-based management interface to trusted networks or users only. Monitor network traffic for suspicious activity related to the interface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73703. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart