Junglewise Threat Intelligence

CVE-2026-73765: HPE AOS-CX authenticated path traversal in API endpoints

CVE-2026-73765 · Severity: high · CVSS 7.2 · Published 2026-09-01

Vendors: Hpe.

Executive brief

HPE AOS-CX is a network operating system used in enterprise switching infrastructure. Authenticated attackers with API access can exploit path traversal vulnerabilities to write arbitrary files to the underlying system, potentially achieving remote code execution and compromising network device availability and integrity.

Technical details

The vulnerability is an authenticated path traversal flaw in AOS-CX API endpoints that allows attackers to bypass directory restrictions and write arbitrary files to the operating system. The attack requires valid API credentials but does not require additional user interaction. Successful exploitation can lead to arbitrary file write and remote code execution on the affected network device. HPE has released patches to address this issue; users should update to patched versions immediately.

Affected products

  • HPE AOS-CX

Timeline

  • 2026-09-01: disclosed

References