CVE-2026-76742 PUBLISHED

Authentication Bypass in the Web Management Interface of AOS-S

Assigner: hpe
Reserved: 19.08.2026 Published: 06.10.2026 Updated: 07.10.2026

Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to gain unauthorized access to the affected system.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Hewlett Packard Enterprise (HPE)
Product AOS-Switch (AOS-S)
Versions Default: affected
  • affected from 16.11.0000 to 16.11.0031 (incl.)

Credits

  • Internal security research (HPE Networking). reporter

References