CVE-2026-73781
8.4Hewlett Packard Enterprise · AOS-CX
A stored cross-site scripting (XSS) vulnerability in the HPE AOS-CX web management interface allows an authenticated attacker to execute arbitrary scripts in an administrator's browser.
Executive summary
An authenticated remote attacker can exploit a stored XSS vulnerability in the HPE AOS-CX web management interface to compromise administrative sessions and execute arbitrary code in a victim's browser.
Vulnerability
This is a stored cross-site scripting (XSS) flaw located within the web-based management interface. The vulnerability requires an authenticated attacker with high privileges to inject malicious scripts that execute within the context of an administrative user's session.
Business impact
Successful exploitation poses a significant risk to network infrastructure integrity, as an attacker could hijack administrative sessions, modify configurations, or perform unauthorized actions on the network switch. Given the CVSS score of 8.4, this vulnerability is classified as High severity, reflecting the potential for complete compromise of the management interface and subsequent impact on network operations.
Remediation
Immediate Action: Review the official HPE security advisory and apply the recommended firmware updates as soon as they become available for your specific model and version.
Proactive Monitoring: Implement strict access control lists for the management interface and monitor administrative logs for suspicious script injections or unusual activity following user logins.
Compensating Controls: Restrict access to the web management interface to trusted management subnets only and utilize a Web Application Firewall where feasible to inspect and block malicious web requests.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing HPE AOS-CX switches should prioritize the identification of affected units within their environment. Because this vulnerability targets the administrative interface, administrators should exercise extreme caution when accessing the web console until patches are applied to mitigate the risk of session hijacking and unauthorized command execution.
More Hewlett Packard Enterprise CVEs
Sources
Originally found and disclosed by This vulnerability was discovered by internal security research at HPE Networking., per the CVE Program record.