Junglewise Threat Intelligence

CVE-2026-73731: HPE Networking Fabric Composer reflected XSS in web management interface

CVE-2026-73731 · Severity: medium · CVSS 6.1 · Published 2026-09-01

Technologies: Arubanetworks Fabric Composer, Hpe Networking Fabric Composer. Vendors: Arubanetworks, Hpe.

Executive brief

HPE Networking Fabric Composer is a web-based management platform for network fabric infrastructure. An unauthenticated attacker can exploit a reflected cross-site scripting (XSS) vulnerability to inject malicious scripts into the management interface, potentially compromising administrator sessions and allowing unauthorized control of the network infrastructure.

Technical details

This is a reflected cross-site scripting (XSS) vulnerability in the web-based management interface of HPE Networking Fabric Composer. The vulnerability allows an unauthenticated remote attacker to inject arbitrary script code that executes in a victim's browser within the context of the affected interface. Attack vector is network-based and requires no authentication, but typically requires user interaction (victim must click a malicious link). A successful exploit could enable session hijacking, credential theft, or unauthorized administrative actions on the managed network fabric.

Affected products

  • HPE Networking Fabric Composer

Timeline

  • 2026-09-01: disclosed

References

Related threats