CVE-2026-73750
—Authenticated DoS or Elevated-Privilege RCE in HPE Authentication Module
HPE (CNA: [email protected]) has disclosed a flaw in an authentication module that improperly processes malformed or truncated input (CWE-284, improper access control). An authenticated remote attacker triggers it by sending specially crafted input from a compromised or hostile authentication server, with no user interaction required. Successful exploitation could cause a denial-of-service or, potentially, remote code execution with elevated privileges, consistent with the high CVSS 3.1 score of 8.8 (confidentiality, integrity and availability all rated high). Affected organizations are those running the impacted HPE product where the device or client authenticates against a server that could be compromised, misconfigured, or impersonated by an attacker. As of now there is no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS estimates only a 0.5% chance of exploitation in the next 30 days (39th percentile), indicating low near-term exploitation risk.
What to do: Identify which HPE products in your environment rely on the affected authentication module and subscribe to the HPE Support Center / HPE security advisories for CVE-2026-73750 to obtain the affected and fixed version list, then patch promptly when released. In the interim, restrict the systems' exposure by ensuring they authenticate only against trusted, well-protected authentication servers, limiting network access to those services, and monitoring for crashes or restarts of the authentication component. Because exploitation requires only existing (low) privileges and no user interaction, prioritize environments where authentication servers are shared, externally reachable, or at higher risk of compromise.
| HPE Authentication module of an HPE product (specific product line not identified in available data) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful exploitation could result in a Denial-of-Service or potential remote code execution with elevated privileges.
- Vendors
- hpe
- Products
- arubaos-cx
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.