Access Control Vulnerability in AOS-CX by HPE
CVE-2026-73762

6.6MEDIUM

Key Information:

Vendor

HP (HP)

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-73762?

A vulnerability exists in the API endpoint of AOS-CX, allowing remote attackers to bypass specific access controls. This flaw could potentially give unauthorized users access to management functionalities that should be safeguarded by established access control policies. Organizations should remain vigilant and consider applying recommended security patches to mitigate potential risks.

Affected Version(s)

AOS-CX 10.18.0000 <= 10.18.0001

AOS-CX 10.18.0000 <= 10.18.0001

AOS-CX 10.17.0000 <= 10.17.1021

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability was discovered by internal security research at HPE Networking.
.