Junglewise Threat Intelligence

CVE-2026-73758: HPE Arista AOS-CX API privilege escalation

CVE-2026-73758 · Severity: medium · CVSS 6.5 · Published 2026-09-01

Vendors: Hpe.

Executive brief

AOS-CX is a network operating system used to manage switches and network infrastructure. A flaw in its API endpoint allows authenticated users with low privilege accounts to escalate their access and change system settings they should not be able to modify, potentially disrupting network operations or configuration integrity.

Technical details

A privilege escalation vulnerability exists in the API endpoint of AOS-CX that allows authenticated low-privilege operators to modify settings beyond their intended authorization scope. The vulnerability requires valid authentication credentials (low-privilege user account) to exploit but does not require elevated starting privileges. Successful exploitation enables a malicious or compromised low-privilege operator account to alter critical system settings, potentially affecting network availability or security posture. Fix information is available through HPE security advisories.

Affected products

  • HPE Arista AOS-CX

Timeline

  • 2026-09-01: disclosed

References