CVE-2026-73756: Unauthenticated Sensitive Information Disclosure via Man-in-the-Middle in AOS-CX via API Endpoint
Published Sep 1, 2026
·Updated
A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data which could be used to further compromise the confidentiality of the affected system.
Affected Software
1 affected component
AOS-CX
Event History
Sep 1, 2026
CVE Published
via MITRE·08:28 PM
Data Sourced
via MITRE·08:28 PM
DescriptionSeverity
Frequently Asked Questions
1
Does exploitation require credentials or user interaction?
No credentials or user interaction are required. The attacker must be able to conduct a man-in-the-middle attack against the affected API communication.
2
What is the expected impact if exploitation succeeds?
An attacker could obtain sensitive information from the affected system. The available data indicates a confidentiality impact, with no indicated integrity or availability impact.