CVE-2026-73765: Authenticated Path Traversal Vulnerabilities Lead to Remote Code Execution in AOS-CX
Published Sep 1, 2026
·Updated
Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerabilities allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.
Affected Software
1 affected component
Aruba AOS-CX
Event History
Sep 1, 2026
CVE Published
via MITRE·08:28 PM
Data Sourced
via MITRE·08:28 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires authenticated access with high privileges. It is remotely reachable over the network and does not require user interaction.
2
What is the likely impact of successful exploitation?
An attacker can write arbitrary files to the underlying operating system through affected API endpoints. This could be used to achieve remote code execution, with high impact to confidentiality, integrity, and availability.