← Terug naar overzicht

A stored cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of HPE Networking Fabric Composer. An authenticated low-privilege operator user can inject malicious scripts that are later executed in the browser of an administrative user. A successful exploit allows arbitrary script execution in the victim's browser within the context of the affected interface. This represents a privilege escalation risk, as a lower-privileged user can potentially compromise administrative sessions. The vulnerability requires authentication, limiting but not eliminating the attack surface. HPE has published a security bulletin addressing the issue. Organizations using HPE Networking Fabric Composer should apply available patches or mitigations promptly.

Affected products

  • HPE Networking Fabric Composer

Related CVE's

  • CVE-2026-73700

Categories

  • Network Infrastructure
  • Web Technologies