Junglewise Threat Intelligence

CVE-2026-73760: HPE AOS-CX path traversal in web management interface

CVE-2026-73760 · Severity: medium · CVSS 6.5 · Published 2026-09-01

Vendors: Hpe.

Executive brief

AOS-CX is a network operating system used in enterprise switches and routers. An authenticated path traversal flaw in its web-based management interface allows an attacker with valid credentials to read sensitive files from the underlying system, potentially exposing configuration data, credentials, and other confidential information that could enable further compromise.

Technical details

This is a path traversal vulnerability affecting the web-based management interface of AOS-CX. The vulnerability requires prior authentication, limiting the attack surface to users or systems with valid management credentials. An attacker can exploit the flaw to escape directory restrictions and access arbitrary files on the operating system using directory traversal sequences (e.g., "../" or "..\"). Successful exploitation enables unauthorized read access to sensitive files including system configuration, credentials, and application data. Patches are expected from HPE; users should consult the HPE security advisory for patched versions and interim mitigations.

Affected products

  • HPE AOS-CX

Timeline

  • 2026-09-01: disclosed

References