Description
A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality that should be restricted by the configured access control policy.
Published: 2026-09-01
Score: 6.6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authorization bypass in the API endpoint of HPE AOS‑CX that permits a remote actor to circumvent existing access controls. This flaw allows access to management functionality that should be restricted by the configured policy, potentially compromising the confidentiality, integrity, or availability of system management capabilities. The weakness is an improper authorization flaw, consistent with common access control violations.

Affected Systems

The affected product is Hewlett Packard Enterprise’s AOS‑CX. No specific affected versions are provided in the CVE metadata, so all installed instances should be considered potentially vulnerable until further information is obtained. Check the HPE support reference for any version guidance.

Risk and Exploitability

The CVSS score of 6.6 indicates a medium severity vulnerability, and an EPSS score is not available, so the exact likelihood of exploitation cannot be quantified. The vulnerability remains unnoted in the CISA KEV catalog. Attackers can exploit the flaw remotely by sending crafted requests to the API endpoint, bypassing authorization checks without local privileges. The risk is that unauthenticated or low‑privileged actors could gain elevated management access if the API is exposed to untrusted networks.

Generated by OpenCVE AI on September 2, 2026 at 01:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE AOS‑CX security update or patch that addresses the authorization bypass (refer to the linked HPE support document).
  • Restrict API access by enforcing network segmentation and limiting allowed IP ranges to the AOS‑CX API endpoint.
  • Verify that current access control policies are correctly enforced and deny all unauthorized users from management endpoints.
  • Disable any unused API services that rely on legacy authentication mechanisms if possible, following vendor recommendations.

Generated by OpenCVE AI on September 2, 2026 at 01:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality that should be restricted by the configured access control policy.
Title Authorization Bypass in the API Endpoint of AOS-CX Leads to Unauthorized Access
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:28:20.954Z

Reserved: 2026-08-13T16:38:49.644Z

Link: CVE-2026-73762

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T21:18:42.963

Modified: 2026-09-01T21:18:42.963

Link: CVE-2026-73762

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T02:00:13Z

Weaknesses