CVE-2026-73703
nicheStored XSS in HPE Aruba Networking Fabric Composer web management interface
CVE-2026-73703 is a stored cross-site scripting (XSS) flaw in the web-based management interface of HPE Aruba Networking Fabric Composer, a platform used to orchestrate and manage Aruba networking infrastructure. An unauthenticated attacker positioned on an adjacent network (for example, on the same management segment or VLAN as the appliance) can inject malicious script that is stored by the interface; when a user of the interface views the affected content, the script executes. A successful attacker gains the ability to run arbitrary script code in the victim's browser within the context of the management interface, which can enable session hijacking or administrative actions performed as the logged-in victim. Only organizations running HPE Aruba Fabric Composer are affected, and because the attack vector is adjacent (AV:A), attackers generally need some foothold on or access to the management network. Exploitation is not currently observed: there is no known in-the-wild activity, no public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a ~0.2% chance of exploitation in the next 30 days.
What to do: Check the HPE security advisory for CVE-2026-73703 and upgrade Fabric Composer to a fixed release as soon as one is identified, since the data available here does not include patched version numbers. Until then, restrict access to the Fabric Composer management interface to trusted management networks or VLANs and limit which users browse it from untrusted segments, because exploitation requires adjacent network access. Watch the HPE advisory and this dashboard for updates on affected versions and any published proof-of-concept.
| HPE (Aruba Networks) HPE Aruba Networking Fabric Composer (web-based management interface) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.