Junglewise Threat Intelligence

CVE-2026-73775: HPE AOS-CX API endpoint information disclosure

CVE-2026-73775 · Severity: high · CVSS 7.7 · Published 2026-09-01

Vendors: Hpe.

Executive brief

HPE AOS-CX is a network operating system used in data center switches and fabric management. Vulnerabilities in its API endpoint allow an authenticated attacker with low-level access to retrieve sensitive system information that could be used to compromise additional network services, potentially leading to further network intrusion or lateral movement.

Technical details

The vulnerability exists in the API endpoint of HPE AOS-CX and allows information disclosure to authenticated users with low privileges. The flaw enables an attacker to retrieve sensitive information through the API without proper authorization controls. No additional technical details regarding the specific API endpoint, authentication mechanism, or vulnerable component are disclosed in the advisory. The attack requires network access to the API endpoint and valid low-privilege credentials. A successful exploit allows information gathering that may facilitate further attacks against network services. Patches are expected to be available from HPE.

Affected products

  • HPE AOS-CX <UNKNOWN>

Timeline

  • 2026-09-01: disclosed

References