Description
A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information from the vulnerable system.
Published: 2026-09-01
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an authenticated low‑privilege operator to retrieve sensitive session information via the AOS‑CX API endpoint. The flaw stems from missing or improper authorization checks, enabling a privilege escalation path that bypasses normal access controls. Once the attacker obtains the data, they can increase their privileges and gain broader access to system resources.

Affected Systems

Hewlett Packard Enterprise AOS‑CX. No specific vulnerable version was listed in the advisory; users should verify that their deployment is not on an affected release.

Risk and Exploitability

The CVSS score of 5.7 indicates moderate severity, and the EPSS score is currently unavailable. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated as a low‑privilege operator and to perform a defined user action. Because authentication is a prerequisite, the attack surface is limited to compromised or poorly secured accounts, but the lack of authorization checks creates a straightforward privilege escalation route once inside the system.

Generated by OpenCVE AI on September 2, 2026 at 01:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update AOS‑CX to the latest version that includes the patch for this privilege escalation issue. Consult HPE support for the specific patch release.
  • Restrict the API endpoint to only those accounts that truly need access, removing or disabling unnecessary operator privileges.
  • Apply network segmentation or firewall rules to isolate the management interface from untrusted networks and reduce the attack surface.

Generated by OpenCVE AI on September 2, 2026 at 01:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-285

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information from the vulnerable system.
Title Privilege Escalation via Unauthorized Access to Sensitive Session Information
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:28:10.325Z

Reserved: 2026-08-13T16:38:28.876Z

Link: CVE-2026-73755

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T21:18:42.090

Modified: 2026-09-01T21:18:42.090

Link: CVE-2026-73755

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T02:00:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-285

    Improper Authorization