CVE-2026-73775
largeSensitive Information Exposure via Authenticated API in HPE ArubaOS-CX
HPE ArubaOS-CX, the network operating system for Aruba's campus and data-center switch line, contains an information-disclosure flaw (CWE-200) in one of its API endpoints. A remote attacker who already holds a low-privileged account can send requests to the API and retrieve sensitive information the account should not be able to access, with no user interaction required. The retrieved data could be used to gain further access to network services supported by AOS-CX; the CVSS vector indicates high confidentiality impact only, with no integrity or availability impact. Any organization running AOS-CX switches with the API enabled and low-privileged accounts is potentially affected, though specific affected firmware version ranges were not included in the available data. No exploitation has been observed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns only a ~0.3% probability of exploitation within 30 days.
What to do: Monitor for and apply the patched AOS-CX firmware release listed in the HPE Aruba advisory for CVE-2026-73775 for your switch model/branch. In the interim, restrict access to the switch REST/API (management ACLs, dedicated management network) and review which low-privileged accounts have API access. Because no in-the-wild exploitation or public PoC is known, patching on a normal maintenance cycle is reasonable, but prioritize switches with exposed or broadly reachable management interfaces.
| HPE ArubaOS-CX | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by AOS-CX.
- Vendors
- hpe
- Products
- arubaos-cx
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.