← Browse

CVE-2026-73762

Low

No strong exploitation signal.

CVSS base
6.6 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
EPSS — probability of exploitation (30 days)
0.2%
12.7th percentile
CISA KEV
Not listed
Weakness / dates
CWE-284
Published 2026-09-01 · modified 2026-09-04

CVSS breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

Attack VectorNNetwork
Attack ComplexityLLow
Privileges RequiredHHigh
User InteractionNNone
ScopeCChanged
ConfidentialityLLow
IntegrityLLow
AvailabilityLLow

Timeline

Description

A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality that should be restricted by the configured access control policy.

Affected

hpe

References

Official: NVD · CVE.org