Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-73779

CVE-2026-73779: AOS-CX Switches Auth Bypass Vulnerability

CVE-2026-73779 is an authentication bypass flaw in AOS-CX switches that allows unauthenticated remote attackers to circumvent existing authentication controls. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-73779 Overview

CVE-2026-73779 is an authentication bypass vulnerability in the operating system of HPE Aruba Networking AOS-CX switches. An unauthenticated actor on an adjacent network can circumvent existing authentication controls. Successful exploitation compromises system integrity and exposes sensitive information stored on or transiting the switch.

The flaw is tracked under CWE-269: Improper Privilege Management and affects the switch operating system rather than a specific management protocol. HPE published a security advisory addressing the issue.

Critical Impact

An unauthenticated attacker with adjacent network access can bypass authentication on AOS-CX switches, compromising system integrity and exposing sensitive network data.

Affected Products

  • HPE Aruba Networking AOS-CX switch operating system
  • AOS-CX managed switching platforms deployed in enterprise and campus networks
  • See the HPE Security Advisory for the full list of affected models and firmware versions

Discovery Timeline

  • 2026-09-01 - CVE-2026-73779 published to NVD
  • 2026-09-03 - Last updated in NVD database

Technical Details for CVE-2026-73779

Vulnerability Analysis

The vulnerability resides in authentication handling within the AOS-CX operating system. An adjacent network attacker can bypass authentication controls without valid credentials. Because the scope is changed, exploitation impacts resources beyond the vulnerable switch itself, including downstream systems and management planes that trust the compromised device.

The attack complexity is high, indicating that specific network conditions, timing, or configuration state must be met for reliable exploitation. Once the attacker circumvents authentication, they gain the ability to read and modify switch data, alter configuration, and pivot into segments the switch bridges or routes.

Exploitation does not require user interaction. No public proof-of-concept code has been observed, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Root Cause

The root cause is improper privilege management [CWE-269] in the AOS-CX authentication path. The operating system fails to consistently enforce authentication decisions before granting privileged operations. HPE has not published the specific code-level detail, but the CWE classification indicates that privilege assignment or verification is performed incorrectly for certain request flows.

Attack Vector

The attacker must be on a network adjacent to the target switch, such as the same broadcast domain, management VLAN, or a directly connected Layer 2 segment. Remote exploitation across routed boundaries is not in scope. Once positioned, the attacker sends crafted requests to the switch that exercise the flawed authentication logic and gain access equivalent to an authenticated management session.

No verified exploit code is available. Refer to the HPE Security Advisory for vendor-provided technical detail.

Detection Methods for CVE-2026-73779

Indicators of Compromise

  • Unexpected administrative sessions on AOS-CX switches originating from adjacent-network hosts that are not part of the network operations inventory
  • Configuration changes, user additions, or SNMP community modifications outside of approved change windows
  • Authentication log gaps or entries where privileged actions occur without a preceding successful login event
  • Unusual outbound connections from the switch management interface to attacker-controlled hosts

Detection Strategies

  • Baseline all administrative access to AOS-CX switches and alert on sessions from unapproved source addresses within adjacent VLANs
  • Compare running configurations against known-good baselines on a scheduled basis and flag drift
  • Correlate AAA, TACACS+, and RADIUS logs with switch-side authentication events to detect access granted without a matching AAA transaction

Monitoring Recommendations

  • Forward AOS-CX syslog, authentication, and configuration audit events to a centralized SIEM or data lake for retention and correlation
  • Enable and monitor show accounting log and show audit trail output for privileged command execution
  • Monitor management VLANs for ARP anomalies and unauthorized hosts that could indicate an adjacent-network foothold

How to Mitigate CVE-2026-73779

Immediate Actions Required

  • Inventory all AOS-CX switches and cross-reference firmware versions against the fixed releases listed in the HPE Security Advisory
  • Apply the vendor-supplied firmware update to affected switches during the next available maintenance window
  • Restrict management-plane access to a dedicated, tightly controlled out-of-band management network
  • Rotate local administrative credentials, SNMP communities, and API tokens on switches that were exposed before patching

Patch Information

HPE has released fixed firmware for AOS-CX. Consult the HPE Security Advisory hpesbnw05134en_us for the exact version numbers per switch family. Apply the update to every affected device rather than a representative sample, since the vulnerability is in the shared operating system.

Workarounds

  • Enforce management VLAN isolation so only authorized jump hosts can reach switch management interfaces
  • Apply port-level access control lists to block untrusted hosts from initiating management-protocol traffic to the switch
  • Disable unused management services and protocols on the switch to reduce the exposed attack surface
  • Require multi-factor authentication on jump hosts and bastion systems used to administer AOS-CX devices
bash
# Example: restrict management access to an authorized subnet on AOS-CX
configure terminal
access-list ip MGMT-ACL
  10 permit tcp 10.10.0.0/24 any eq ssh
  20 permit tcp 10.10.0.0/24 any eq https
  30 deny  any any any
exit
interface mgmt
  ip access-group MGMT-ACL in
exit

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.