CVE-2026-73781
largeStored XSS in HPE ArubaOS-CX Web Management Interface
CVE-2026-73781 is a stored cross-site scripting (XSS) flaw (CWE-79) in the web-based management interface of HPE ArubaOS-CX network switches. An attacker who already holds authenticated, high-privileged (administrative-level) access to the interface can store malicious script content, which then executes when an administrative user views the affected page in their browser (CVSS: AV:N/AC:L/PR:H/UI:R/S:C, scored 8.4 High). Successful exploitation lets the attacker run arbitrary script in the victim admin's browser in the context of the management interface, potentially enabling session hijacking or unauthorized configuration actions with that admin's privileges (C/I/A rated High). Only deployments running ArubaOS-CX with the web management interface enabled and in use by administrators are exposed; affected release ranges are not specified in the available data. No public proof-of-concept, no CISA KEV listing, and a low EPSS of 0.3% (20th percentile) indicate no known exploitation at this time.
What to do: Review HPE's Aruba security advisory for CVE-2026-73781 to identify affected AOS-CX release ranges and upgrade to the patched firmware once published. In the interim, restrict access to the switch web management interface (management VLAN/ACLs), minimize the number of administrative accounts, and avoid untrusted content entered into the interface. Because exploitation requires existing high-privileged access, also audit admin accounts and review recent configuration or account changes for signs of tampering.
| HPE ArubaOS-CX (AOS-CX) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
- Vendors
- hpe
- Products
- arubaos-cx
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.