CVE-2026-73765
massAuthenticated Path Traversal in HPE ArubaOS-CX Switch API Enables RCE
HPE has disclosed CVE-2026-73765, an authenticated path traversal flaw (CWE-22) in the API endpoints of ArubaOS-CX, the network operating system that runs on HPE Aruba Networking CX-series switches. An attacker with high-privilege (administrator-level) credentials sends a crafted request to an affected API endpoint, and unsanitized path handling lets file writes escape their intended directory on the underlying operating system. Because arbitrary file write is possible, the flaw can be leveraged to achieve remote code execution on the switch; the CVSS 3.1 vector (AV:N/AC:L/PR:H/UI:N/S:U) reflects that network access and privileged authentication are required, but no user interaction. Any organization running ArubaOS-CX switches, typically in enterprise campus, branch, or data-center networks, is potentially affected, though the available data does not specify which firmware versions or which API endpoints are impacted. There is no evidence of exploitation so far: the flaw is not in CISA KEV, EPSS assigns a 0.7% probability of exploitation within 30 days (around the median), and no public proof-of-concept is known.
What to do: Upgrade ArubaOS-CX switches to the fixed firmware release identified in HPE's security advisory (specific versions are not listed in this data), which is the primary remediation since exploitation requires only admin-level credentials. In the interim, restrict access to the switch REST/API endpoints and management interface to trusted management networks and audit which accounts hold administrator privileges, since high-privilege authentication is a prerequisite. Monitor the HPE Aruba security alerts portal for the advisory text and updated firmware releases.
| HPE ArubaOS-CX | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerabilities allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.
- Vendors
- hpe
- Products
- arubaos-cx
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.