CVE-2026-73777
largeAuthentication bypass in HPE Aruba AOS-CX switch REST API
CVE-2026-73777 describes an improper authentication flaw (CWE-287) in the API endpoint of HPE Aruba Networking AOS-CX switches. A remote, unauthenticated actor with network reachability to the switch's API can trigger the flaw to circumvent existing authentication controls, though the CVSS vector (AV:N/AC:H) indicates exploitation requires somewhat unusual conditions. Successful exploitation would grant an attacker unauthenticated access to the device's management API, with CVSS scoring potential high impact to the confidentiality, integrity, and availability of the switch, for example through unauthorized configuration changes. Any organization running AOS-CX switches whose API is reachable by untrusted actors, typically over management networks and in some deployments from the internet, is potentially affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates only a 0.3% probability of exploitation within 30 days.
What to do: Check the official HPE security advisory for the fixed AOS-CX firmware version applicable to your switch series and upgrade promptly, since specific affected/fixed versions are not included in the available data. Until patched, restrict access to the switch REST API to trusted management networks (management VLANs/ACLs), disable the REST API where it is not required, and avoid exposing the API directly to the internet. Monitor HPE communications for updated version information and any published mitigations.
| HPE ArubaOS-CX (AOS-CX switch operating system, REST/API endpoint) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls.
- Vendors
- hpe
- Products
- arubaos-cx
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.