Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer |
|
| Vendors & Products |
Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer |
Wed, 02 Sep 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. | |
| Title | Unauthenticated Reflected Cross-Site Scripting (XSS) Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2026-09-02T18:57:38.467Z
Reserved: 2026-08-13T16:37:26.896Z
Link: CVE-2026-73731
No data.
Status : Undergoing Analysis
Published: 2026-09-01T20:17:20.703
Modified: 2026-09-02T19:18:03.503
Link: CVE-2026-73731
No data.
OpenCVE Enrichment
Updated: 2026-09-02T16:44:19Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')