MEDIUM · 5.7

CVE-2026-73755

A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sen...

Vulnerability Description

A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information from the vulnerable system.

CVSS Score

5.7

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
HpeArubaos-Cx<= 10.10.1180
HpeAruba Cx 10000-48Y6C \(R8P13A\)-
HpeAruba Cx 10000-48Y6C \(R8P14A\)-
HpeAruba Cx 10000-48Y6C \(S0F98A\)-
HpeAruba Cx 10040 \(S4R58A\)-
HpeAruba Cx 10040 32P \(S4R54A\)-
HpeAruba Cx 10040 32P \(S4R55A\)-
HpeAruba Cx 10040 32P \(S4R56A\)-
HpeAruba Cx 4100I 12-Port \(Jl817A\)-
HpeAruba Cx 4100I 24-Port \(Jl818A\)-
HpeAruba Cx 6000 12G \(R8N89A\)-
HpeAruba Cx 6000 12P \(R8N89B\)-
HpeAruba Cx 6000 12P \(S4R21A\)-
HpeAruba Cx 6000 24G \(R8N87A\)-
HpeAruba Cx 6000 24G \(R8N88A\)-
HpeAruba Cx 6000 24P \(R8N87B\)-
HpeAruba Cx 6000 24P \(R8N88B\)-
HpeAruba Cx 6000 24P \(S4R26A\)-
HpeAruba Cx 6000 24P \(S4R27A\)-
HpeAruba Cx 6000 48G \(R8N85A\)-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-73755?

CVE-2026-73755 is a vulnerability with a CVSS score of 5.7 (MEDIUM). A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sen...

How severe is CVE-2026-73755?

CVE-2026-73755 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-73755?

Check the references section above for vendor advisories and patch information. Affected products include: Hpe Arubaos-Cx, Hpe Aruba Cx 10000-48Y6C \(R8P13A\), Hpe Aruba Cx 10000-48Y6C \(R8P14A\), Hpe Aruba Cx 10000-48Y6C \(S0F98A\), Hpe Aruba Cx 10040 \(S4R58A\).