A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality that should be restricted by the configured access control policy.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) aos-cx |
|
| Vendors & Products |
Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) aos-cx |
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality that should be restricted by the configured access control policy. | |
| Title | Authorization Bypass in the API Endpoint of AOS-CX Leads to Unauthorized Access | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hpe
Published: 2026-09-01T20:28:20.954Z
Updated: 2026-09-02T13:26:17.807Z
Reserved: 2026-08-13T16:38:49.644Z
Link: CVE-2026-73762
Updated: 2026-09-02T13:24:20.925Z
Status : Awaiting Analysis
Published: 2026-09-01T21:18:42.963
Modified: 2026-09-02T19:34:36.770
Link: CVE-2026-73762
No data.