CVE-2026-73703

8.8

Hewlett Packard Enterprise · Fabric Composer

HPE Fabric Composer contains a stored cross-site scripting (XSS) vulnerability in its web-based management interface that allows unauthenticated adjacent attackers to execute arbitrary script code.

Executive summary

An unauthenticated adjacent attacker can exploit a stored cross-site scripting vulnerability in HPE Fabric Composer to execute arbitrary code in the context of a victim's browser session.

Vulnerability

This is a stored cross-site scripting (XSS) vulnerability located within the web-based management interface of the application. It allows an unauthenticated attacker positioned on the adjacent network to inject malicious scripts that execute when a user accesses the affected interface.

Business impact

The exploitation of this vulnerability poses a significant risk to organizational security, as it allows attackers to hijack active user sessions or perform unauthorized actions within the management console. Given the CVSS score of 8.8, this flaw is categorized as high severity and could lead to complete administrative compromise of the fabric management environment, resulting in potential data theft or infrastructure disruption.

Remediation

Immediate Action: Review the vendor advisory provided by Hewlett Packard Enterprise to identify and apply the necessary security updates or configuration changes for versions 7.0.0 through 7.3.3.

Proactive Monitoring: Monitor management interface access logs for anomalous traffic patterns or suspicious script injections originating from the adjacent network.

Compensating Controls: Implement a Web Application Firewall (WAF) with strict input validation and output encoding rules to detect and block malicious script payloads directed at the management interface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The high CVSS score of 8.8 reflects the potential for severe impact on the management layer of the networking infrastructure. Administrators must prioritize applying vendor-supplied patches as soon as they become available to prevent unauthorized script execution and potential session hijacking.

More Hewlett Packard Enterprise CVEs

Sources

Originally found and disclosed by This vulnerability was discovered by internal security research at HPE Networking., per the CVE Program record.