CVE-2026-73753
largeOS Command Injection in HPE ArubaOS-CX (Authenticated Privilege Escalation to Root)
CVE-2026-73753 is an OS command injection flaw (CWE-78) in HPE's ArubaOS-CX network switch operating system. It is triggered when an authenticated low-privileged user (e.g., an operator or read-only account) runs affected command-line operations, causing injected commands to run with unintended privileges. A successful attacker gains the ability to execute arbitrary commands as a privileged (root-level) user on the switch's underlying operating system, enabling full control of the device. Any organization running HPE ArubaOS-CX switches where low-privileged users have CLI or management access is potentially affected. There is currently no known exploitation in the wild, no public proof-of-concept, and the flaw is not in CISA's KEV, with EPSS estimating only a ~0.4% chance of exploitation in the next 30 days.
What to do: Monitor the HPE security advisory for CVE-2026-73753 and apply the fixed ArubaOS-CX firmware release it specifies as soon as available. In the interim, restrict or remove operator-level (low-privileged) CLI/SSH/WebUI accounts on affected switches and limit management-plane access to trusted admin networks. Audit switch configurations for low-privileged local or AAA-authenticated users with command-line access, since those accounts are the attack vector.
| hpe arubaos-cx | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.
- Vendors
- hpe
- Products
- arubaos-cx
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.