Executive brief
HPE Networking Fabric Composer is a web-based management tool for enterprise network fabric devices. A stored cross-site scripting (XSS) vulnerability in its management interface allows an attacker on the adjacent network to inject malicious code that executes when legitimate administrators access the interface, potentially compromising their accounts or stealing sensitive network configuration data.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the web-based management interface of HPE Networking Fabric Composer. An unauthenticated adjacent attacker can inject malicious script code that persists in the application, which then executes in the browser context of authenticated users accessing the interface. The attack requires network adjacency but no prior authentication, and successful exploitation allows arbitrary JavaScript execution in victims' browsers within the interface security context. This could lead to session hijacking, credential theft, or unauthorized network configuration changes.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed