Home ยท Wiki ยท Vulnerabilities & CVEs
type: vulnerability ยท created: 2026-09-04 ยท updated: 2026-09-04 ยท tags: ["cve", "vulnerability", "hpe", "arubaos-cx", "command-injection", "code-execution"] ยท confidence: high ยท severity: high ยท affected_sectors: ["Technology", "Government", "Defence", "Education"] ยท au_impact: true

CVE-2026-73750

Affected product: HPE ArubaOS-CX โ€” low-privilege authenticated command/code execution

Patched version: Fixed in versions released with HPE's 3 September 2026 ArubaOS-CX bulletin (release branches 10.10โ€“10.18)

Active exploitation: No โ€” no active exploitation or public PoCs reported at publication

Assessment

CVE-2026-73750 is one of the higher-rated flaws in HPE's 24-item ArubaOS-CX patch bundle (rated up to 8.8), covering authenticated command or code execution usable by a low-privilege account on affected switches. The web-interface command-injection variant in the wider bundle illustrates how a network operator or a low-privilege administrator account can escalate to full device compromise. While it requires authentication and is therefore less exposed than the critical unauthenticated CVE-2026-73749, it is part of the same patch cycle, so Australian switch operators should apply the complete AOS-CX bundle rather than treating any single CVE in isolation, and review local admin account posture on management interfaces.