CVE-2026-73758: Authenticated Privilege Escalation Vulnerability via Broken Access Control in AOS-CX
Published Sep 1, 2026
·Updated
A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.
Event History
Sep 1, 2026
CVE Published
via MITRE·08:28 PM
Data Sourced
via MITRE·08:28 PM
DescriptionSeverity
Frequently Asked Questions
1
Who can exploit this vulnerability?
An authenticated user with a low-privilege operator account can exploit the affected API endpoint. No user interaction is required.
2
What is the impact of successful exploitation?
An attacker could change the state of certain settings on a vulnerable system, despite having only low-privilege operator access.