CVE-2026-73779
largeAuthentication Bypass in HPE Aruba AOS-CX Switch Operating System
HPE's ArubaOS-CX (AOS-CX) switch operating system contains an improper privilege management flaw (CWE-269) that allows an unauthenticated actor to circumvent existing authentication controls. Per the CVSS vector, the attacker must have access to an adjacent network segment (AV:A), needs no credentials or user interaction, but exploitation carries high attack complexity. A successful bypass can compromise system integrity and expose sensitive information, with high confidentiality and integrity impact and a scope change indicating the impact can extend beyond the vulnerable component. Anyone operating HPE Aruba switches running the AOS-CX operating system is potentially affected; the affected firmware branches/versions are not specified in the available data. As of now there are no known exploits, no public proof-of-concept, the issue is not in CISA KEV, and EPSS assigns a low 0.2% probability of exploitation within 30 days.
What to do: Check the HPE security advisory for CVE-2026-73779 to identify affected AOS-CX firmware branches and upgrade to the fixed release it specifies. In the meantime, restrict which devices share a network segment or management path with AOS-CX switches (segmentation, management ACLs) since adjacent access is required, and monitor switch logs for unexplained authentication or privilege events.
| HPE ArubaOS-CX (AOS-CX) switch operating system | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could compromise system integrity and further expose sensitive information.
- Vendors
- hpe
- Products
- arubaos-cx
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.