Description
An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.
Published: 2026-09-01
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a command‑injection flaw exposed through the web‑based management console of HPE AOS‑CX. An authenticated user with low‑privilege accounts can provide crafted input that is passed directly to the operating system, enabling arbitrary command execution. This flaw allows the attacker to run any system commands, potentially gaining full control of the underlying OS, compromising data confidentiality, integrity, and disrupting availability.

Affected Systems

HPE AOS‑CX systems are affected. No specific version numbers are listed in the CNA disclosure, so any installation of the AOS‑CX platform that exposes the web management interface remains vulnerable unless patched or upgraded.

Risk and Exploitability

The CVSS score of 8.8 classifies the vulnerability as High severity. The EPSS score is not available, and the flaw is not currently listed in the CISA KEV catalog. The attack vector is remote; it requires authentication to a low‑privileged user account, but once authenticated the attacker can exploit the flaw over the network. Because the flaw permits arbitrary command execution, the impact is potentially very high for affected systems.

Generated by OpenCVE AI on September 2, 2026 at 01:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE AOS‑CX firmware or patch that fixes the command‑injection issue.
  • Enforce least‑privilege access on the web‑based management interface, removing low‑privileged users from the ability to submit commands.
  • Restrict external access to the management interface via network segmentation or firewall rules, allowing only trusted management networks.

Generated by OpenCVE AI on September 2, 2026 at 01:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.
Title Authenticated Remote Command Injection in AOS-CX Web-based Management Interface
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:28:04.573Z

Reserved: 2026-08-13T16:38:28.876Z

Link: CVE-2026-73751

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T21:18:41.647

Modified: 2026-09-01T21:18:41.647

Link: CVE-2026-73751

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T02:00:13Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')