Junglewise Threat Intelligence

CVE-2026-73762: HPE AOS-CX API access control bypass

CVE-2026-73762 · Severity: medium · CVSS 6.6 · Published 2026-09-01

Vendors: Hpe.

Executive brief

AOS-CX is HPE's network operating system used in Arista switches and data center infrastructure. A vulnerability in its API endpoint allows remote attackers to bypass access controls and gain unauthorized access to management functions that should be restricted by policy, potentially leading to unauthorized configuration changes or data exposure.

Technical details

This vulnerability is an access control bypass in the AOS-CX API endpoint that fails to properly enforce configured access control policies. A remote attacker can exploit this flaw without authentication to circumvent restrictions and access management functionality that should be protected. The vulnerability allows unauthorized API calls to reach protected management endpoints, potentially enabling configuration modification, credential theft, or operational disruption. The attack vector is network-based with no user interaction required.

Affected products

  • HPE AOS-CX

Timeline

  • 2026-09-01: disclosed

References