CVE-2026-73700
moderateStored XSS in HPE Aruba Networking Fabric Composer Management Interface
CVE-2026-73700 is a stored cross-site scripting (CWE-79) flaw in the web-based management interface of HPE Networking (Aruba) Fabric Composer. A user with only low-privilege operator access can inject malicious script that is stored by the interface and later executed when an administrative user views the affected content in their browser. Successful exploitation lets the attacker run arbitrary script in the admin's browser in the context of the management interface, potentially enabling actions taken as that admin, credential/cookie theft, or tampering with the management session. Only organizations running HPE Aruba Networking Fabric Composer are affected, and exploitation requires an attacker to first hold an authenticated operator-level account. Exploitation status is currently low: there is no known public proof-of-concept, it is not in CISA KEV, and EPSS estimates only about a 0.3% chance of exploitation in the next 30 days.
What to do: Apply the update referenced in the HPE security advisory for CVE-2026-73700 (check the HPE support portal for the fixed release for your Fabric Composer version, as no version numbers are provided in this data). Until patched, restrict access to the Fabric Composer web UI to trusted management networks, review and minimize active operator-level accounts, and monitor administrative sessions for unexpected script-driven actions. Note that exploitation requires valid operator credentials plus an administrator viewing attacker-controlled content, so credential hygiene and UI access limits meaningfully reduce risk.
| arubanetworks (HPE) Networking Fabric Composer (web-based management interface) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.