


Perceptive Security
SOC/SIEM Consultancy

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a st…
Published:
1 september 2026 om 00:00:00
Alert date:
1 september 2026 om 23:04:25
Source:
nvd.nist.gov
Network Infrastructure, Web Technologies
A stored cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of HPE Networking Fabric Composer. An authenticated low-privilege operator user can inject malicious scripts that are later executed in the browser of an administrative user. A successful exploit allows arbitrary script execution in the victim's browser within the context of the affected interface. This represents a privilege escalation risk, as a lower-privileged user can potentially compromise administrative sessions. The vulnerability requires authentication, limiting but not eliminating the attack surface. HPE has published a security bulletin addressing the issue. Organizations using HPE Networking Fabric Composer should apply available patches or mitigations promptly.
Technical details
Mitigation steps:
Affected products:
HPE Networking Fabric Composer
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-73700
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
