Executive brief
HPE Networking Fabric Composer is a web-based management platform for network fabric infrastructure. An unauthenticated attacker can exploit a reflected cross-site scripting (XSS) vulnerability to inject malicious scripts into the management interface, potentially compromising administrator sessions and allowing unauthorized control of the network infrastructure.
Technical details
This is a reflected cross-site scripting (XSS) vulnerability in the web-based management interface of HPE Networking Fabric Composer. The vulnerability allows an unauthenticated remote attacker to inject arbitrary script code that executes in a victim's browser within the context of the affected interface. Attack vector is network-based and requires no authentication, but typically requires user interaction (victim must click a malicious link). A successful exploit could enable session hijacking, credential theft, or unauthorized administrative actions on the managed network fabric.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed