Junglewise Threat Intelligence

CVE-2026-73779: HP AOS-CX authentication bypass in operating system

CVE-2026-73779 · Severity: high · CVSS 8.2 · Published 2026-09-01

Vendors: Hp.

Executive brief

HP AOS-CX is a network operating system used in enterprise switches that manage corporate network traffic and security. A vulnerability in the OS allows unauthenticated remote attackers to bypass authentication controls, potentially gaining unauthorized access to switch configuration and sensitive network information, compromising system integrity and expanding their attack surface within the organization.

Technical details

An authentication bypass vulnerability exists in the HP AOS-CX operating system that allows unauthenticated remote attackers to circumvent existing access controls. The vulnerability is network-reachable and requires no prior authentication or user interaction to exploit. Successful exploitation permits an attacker to compromise system integrity and access sensitive information, potentially leading to configuration manipulation and further network compromise. Patch availability has not been specified in the advisory.

Affected products

  • HP AOS-CX

Timeline

  • 2026-09-01: disclosed

References