ZeroHour

CVE-2026-73753

large

OS Command Injection in HPE ArubaOS-CX (Authenticated Privilege Escalation to Root)

CVSS 3.1
8.8 high
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-73753 is an OS command injection flaw (CWE-78) in HPE's ArubaOS-CX network switch operating system. It is triggered when an authenticated low-privileged user (e.g., an operator or read-only account) runs affected command-line operations, causing injected commands to run with unintended privileges. A successful attacker gains the ability to execute arbitrary commands as a privileged (root-level) user on the switch's underlying operating system, enabling full control of the device. Any organization running HPE ArubaOS-CX switches where low-privileged users have CLI or management access is potentially affected. There is currently no known exploitation in the wild, no public proof-of-concept, and the flaw is not in CISA's KEV, with EPSS estimating only a ~0.4% chance of exploitation in the next 30 days.

What to do: Monitor the HPE security advisory for CVE-2026-73753 and apply the fixed ArubaOS-CX firmware release it specifies as soon as available. In the interim, restrict or remove operator-level (low-privileged) CLI/SSH/WebUI accounts on affected switches and limit management-plane access to trusted admin networks. Audit switch configurations for low-privileged local or AAA-authenticated users with command-line access, since those accounts are the attack vector.

Affected
hpe arubaos-cx
Estimated exposure
largelikely on the order of 100,000+ deployed ArubaOS-CX switches enterprise-wide (exact vulnerable count unknown) — ArubaOS-CX is HPE's flagship enterprise campus and data-center switching OS with a very large installed base, but exploitation requires an authenticated low-privileged account, and only a subset of devices expose management/CLI access to…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.

Vendors
hpe
Products
arubaos-cx
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.