CVE-2026-73768
largeImproper CLI Input Validation in HPE ArubaOS-CX Enables Root Command Execution
CVE-2026-73768 is an improper input validation flaw (CWE-20) in the command line interface of HPE ArubaOS-CX, the network operating system running on HPE Aruba CX series switches. It is triggered when a local user with low-privilege CLI access submits malformed input at the command line; the CVSS vector (AV:L/PR:L/UI:R) confirms the attack requires local access, low privileges, and user interaction. A successful exploit lets the attacker execute arbitrary commands with root privileges, giving full control over the switch's operating system, configuration, and traffic handling. Any organization running affected ArubaOS-CX switches is potentially exposed, although the local-only attack vector means attackers must first obtain some form of CLI access to the device. No public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and EPSS estimates only a 0.1% probability of exploitation within 30 days, so no exploitation is currently known.
What to do: Monitor HPE's security advisory for CVE-2026-73768 to identify the affected AOS-CX release branches and upgrade switches to the fixed firmware version once HPE publishes it. Until then, restrict switch CLI access to trusted administrators and avoid granting low-privilege operator-level CLI accounts to untrusted users, since exploitation requires local CLI access. No public exploit, workaround, or in-the-wild exploitation is known at this time.
| HPE ArubaOS-CX | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Successful exploitation could result in the execution of arbitrary commands with root privileges.
- Vendors
- hpe
- Products
- arubaos-cx
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.