Junglewise Threat Intelligence

CVE-2026-73700: HPE Networking Fabric Composer stored cross-site scripting in management interface

CVE-2026-73700 · Severity: critical · CVSS 9 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a web-based management platform for network fabric administration. A low-privilege authenticated operator can inject malicious scripts that execute when administrative users access the interface, potentially allowing attackers to steal credentials, modify network configurations, or impersonate administrators with full system access.

Technical details

This vulnerability is a stored cross-site scripting (XSS) flaw in the web-based management interface of HPE Networking Fabric Composer. An authenticated low-privilege operator can inject malicious JavaScript code that persists in the application and executes in the browser context of any administrative user who views the affected content. The attack requires prior authentication as a low-privilege user and no victim interaction beyond normal usage of the administrative interface. Successful exploitation allows arbitrary script execution with the privileges of the administrative user, potentially leading to account takeover, credential theft, or unauthorized system modifications. Patches are likely available from HPE; consult the referenced support documentation for mitigation guidance.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats