CVE-2026-73766
massAuthenticated command injection in HPE ArubaOS-CX switch API
CVE-2026-7376 is a command injection flaw (CWE-77) in the API endpoint of HPE Aruba's AOS-CX network operating system, which runs on Aruba CX-series campus and data center switches. An authenticated remote attacker who holds administrative privileges on the switch can send crafted API requests that inject arbitrary commands, which are then executed on the underlying operating system. Successful exploitation yields command execution as a privileged OS user, giving the attacker full control over the affected switch with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2, High; the PR:H vector means administrative credentials are required). All organizations running AOS-CX switches whose management/API interface is reachable and whose admin credentials could be compromised are affected; specific affected and fixed firmware versions are not enumerated in the available data. Exploitation has not been reported in the wild: the flaw is not in CISA's KEV catalog, no public proof-of-concept is known, and EPSS estimates a 1.1% chance of exploitation within 30 days.
What to do: Monitor HPE's security advisory ([email protected], CVE-2026-7376) for the list of affected AOS-CX firmware versions and patch to the fixed release once published. In the interim, restrict access to the switch management/REST API to trusted management networks, audit and harden administrative accounts, and review management-plane logs for unexpected API activity or unrecognized admin logins. Since exploitation requires administrative credentials, prioritize protecting or rotating privileged switch credentials.
| HPE ArubaOS-CX | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges to inject arbitrary commands. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
- Vendors
- hpe
- Products
- arubaos-cx
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.