HIGH🇵🇱 Wersja polska

CVE-2026-73703

CVSS 8.8v3.1pub. 2026-09-01upd. 2026-09-02

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Arubanetworks Fabric Composer

    APP
    Arubanetworks
    < 7.3.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-73701CRITICAL9.0same product

An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networ...

CVE-2026-76657CRITICAL10.0same product

Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow...

CVE-2026-19766CRITICAL9.6same product

An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Comp...

CVE-2026-73700CRITICAL9.0same product

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authent...

CVE-2026-76658CRITICAL10.0same product

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an un...