ZeroHour

CVE-2026-73751

Authenticated OS Command Injection in HPE Web-Based Management Interface

CVSS 3.1
8.8 high
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-73751 is a command injection vulnerability (CWE-77) in an HPE product's web-based management interface, in which crafted user-supplied input is passed unsafely to the underlying operating system. An attacker needs only valid low-privileged credentials and network access to the management interface; submitting crafted input then executes arbitrary operating system commands. Successful exploitation yields remote command execution with the privileges of the management service, compromising the confidentiality, integrity, and availability of the host (CVSS 3.1: 8.8 high, AV:N/AC:L/PR:L). Organizations running the affected HPE product whose management interface is reachable by low-privileged users are exposed; the specific product and version ranges are not stated in the available data and should be confirmed in HPE's advisory. There is currently no public proof-of-concept, no CISA KEV listing, and a low EPSS score of 0.4% (30th percentile), so exploitation is not known but the flaw is rated high severity.

What to do: Monitor HPE's security advisory for CVE-2026-73751 to identify the affected product and fixed release, then upgrade promptly once a patch is published. In the meantime, restrict the web-based management interface to trusted management networks (management VLAN or VPN), review which low-privileged accounts can reach it, and audit for unexpected commands or logins. Although no public PoC or in-the-wild exploitation is known, low-privileged authenticated access is the only prerequisite, so do not defer patching.

Affected
Hewlett Packard Enterprise (HPE) Affected HPE product with a web-based management interface (specific product not identified in the source data)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.

Vendors
hpe
Products
arubaos-cx
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.