ZeroHour

CVE-2026-73779

large

Authentication Bypass in HPE Aruba AOS-CX Switch Operating System

CVSS 3.1
8.2 high
EPSS
<1%p7
Published
()
Modified
AI analysis

HPE's ArubaOS-CX (AOS-CX) switch operating system contains an improper privilege management flaw (CWE-269) that allows an unauthenticated actor to circumvent existing authentication controls. Per the CVSS vector, the attacker must have access to an adjacent network segment (AV:A), needs no credentials or user interaction, but exploitation carries high attack complexity. A successful bypass can compromise system integrity and expose sensitive information, with high confidentiality and integrity impact and a scope change indicating the impact can extend beyond the vulnerable component. Anyone operating HPE Aruba switches running the AOS-CX operating system is potentially affected; the affected firmware branches/versions are not specified in the available data. As of now there are no known exploits, no public proof-of-concept, the issue is not in CISA KEV, and EPSS assigns a low 0.2% probability of exploitation within 30 days.

What to do: Check the HPE security advisory for CVE-2026-73779 to identify affected AOS-CX firmware branches and upgrade to the fixed release it specifies. In the meantime, restrict which devices share a network segment or management path with AOS-CX switches (segmentation, management ACLs) since adjacent access is required, and monitor switch logs for unexplained authentication or privilege events.

Affected
HPE ArubaOS-CX (AOS-CX) switch operating system
Estimated exposure
largeon the order of 10^5 deployed AOS-CX switches across roughly 10^4 enterprise sites (estimate) — No install-base or internet-scan counts were provided, so the estimate relies on AOS-CX being a widely deployed enterprise campus and data-center network OS across HPE Aruba CX switch lines since 2017, typically installed in multi-switch…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could compromise system integrity and further expose sensitive information.

Vendors
hpe
Products
arubaos-cx
Weakness
CWE-269
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.