Sceawere

Vulnerability Detail

CVE-2026-73718UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

HPE Networking Fabric Composer XSS

Vulnerability Metadata

Severity
High
Score / CVSS
7.4
Creation Date
2h ago
Vendor
Hewlett Packard Enterprise (HPE)
Product
Fabric Composer
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to access sensitive information if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.4",
  "pubDate": "2026-09-01T20:17:19.290Z",
  "pubdate": "2026-09-01T20:17:19.290Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) or related injection vulnerability exists within the web-based management interface of HPE Networking Fabric Composer.\nThis vulnerability allows an unauthenticated remote attacker to compromise the confidentiality of sensitive information by leveraging a client-side attack vector.\nThe flaw requires an authenticated user of the management interface to interact with a malicious, specially crafted URL, making this a social engineering-dependent exploit.\nSuccessful exploitation permits unauthorized access to sensitive data transmitted or displayed within the authenticated session, which can be further leveraged to escalate access to underlying network services.\nThe risk is significant due to the potential for session hijacking or unauthorized data exfiltration within the administrative domain, necessitating prompt remediation or implementation of defensive controls to prevent unauthorized interaction with the management interface.",
  "technicalDetails": "The vulnerability resides in the web-based management interface of HPE Networking Fabric Composer, which fails to adequately sanitize or validate user-supplied input contained within URL parameters before rendering it in the browser context.\nThe root cause is a failure in the application's output encoding mechanisms, allowing an attacker to inject malicious scripts or instructions into the Document Object Model (DOM) of the management interface.\nThe attack flow initiates when an attacker crafts a malicious URL containing a payload designed to execute within the security context of the target's active session. This URL is then distributed to an authenticated administrative user through social engineering tactics, such as phishing or internal messaging.\nOnce the authenticated user triggers the crafted URL, the web interface processes the malicious input and executes the injected script within the user's browser session. Because the script executes under the authority of the authenticated session, it gains access to sensitive data, session tokens, or API responses normally restricted to the authorized user.\nThe payload may be designed to exfiltrate session cookies to an attacker-controlled server or perform unauthorized actions on behalf of the user, such as modifying configuration settings or retrieving protected network topology data. This represents a critical pivot point where the attacker moves from an external, unauthenticated state to interacting with the network management backend using the stolen context.\nThis vulnerability is classified as remote and does not require pre-existing authentication for the attacker, provided they can reach the management interface and deceive an authenticated user. The impact extends beyond simple information disclosure, as the ability to manipulate the management interface can provide the attacker with deep insights into the network fabric, facilitating further lateral movement or service disruption within the HPE Networking Fabric Composer environment."
}
CVE-2026-73718: HPE Networking Fabric Composer XSS (HIGH Severity, CVSS: 7.4) - Sceawere