Description
A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.
Published: 2026-09-01
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

AOS‑CX exposes a RESTful API endpoint that allows an authenticated user with an operator role to alter critical configuration settings. This privilege‑escalation flaw permits the operator to change system state beyond intended limits, compromising the integrity of the configuration. The attacker could use legitimate credentials to modify network behavior, security policies, or service availability, potentially facilitating further attacks.

Affected Systems

Vendor Hewlett Packard Enterprise, product AOS‑CX. No specific affected versions are listed in the CNA data. The problem resides in the API layer of the system.

Risk and Exploitability

CVSS base score of 6.5 indicates moderate severity. EPSS score is not available, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is an authenticated API call made by an operator account; the attacker must already possess valid credentials. Once the endpoint is accessed, they can change the state of select settings, thereby escalating privileges and potentially destabilizing the system. Because the flaw is tied to authenticated access, general external exposure is limited, but any compromised operator account becomes a vector for this privilege escalation.

Generated by OpenCVE AI on September 2, 2026 at 02:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the HPE patch that addresses the broken access control flaw in AOS‑CX.
  • Reconfigure the system to enforce stricter role‑based access control, removing the ability for operator roles to modify the affected settings. If a patch is not immediately available, temporarily restrict access to the vulnerable API endpoint by firewall rules or disabling it through configuration until the update is applied.
  • Review and audit operator accounts for suspicious activity to detect attempts to modify system settings.

Generated by OpenCVE AI on September 2, 2026 at 02:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.
Title Authenticated Privilege Escalation Vulnerability via Broken Access Control in AOS-CX
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:28:14.391Z

Reserved: 2026-08-13T16:38:28.877Z

Link: CVE-2026-73758

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T21:18:42.503

Modified: 2026-09-01T21:18:42.503

Link: CVE-2026-73758

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T02:15:12Z

Weaknesses

No weakness.