Authenticated Path Traversal Vulnerability in AOS-CX by HPE
CVE-2026-63454

7.2HIGH

Key Information:

Vendor

HP (HP)

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-63454?

An authenticated path traversal vulnerability has been identified in AOS-CX, a network operating system by HPE. This security flaw permits attackers, once they've authenticated, to leverage the command line interface of the underlying operating system to copy arbitrary files to locations accessible by users. This may facilitate further exploitation of the system, including the potential for remote code execution, thereby jeopardizing the confidentiality, integrity, and availability of the data.

Affected Version(s)

AOS-CX 10.17.0000 <= 10.17.1020

AOS-CX 10.17.0000 <= 10.17.1020

AOS-CX 10.16.0000 <= 10.16.1050

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability was discovered by moonv through the HPE Aruba Networking Bug Bounty program.
.