CVE-2026-76743 PUBLISHED

Authentication Bypass Vulnerability in the Management Interface of AOS-S

Assigner: hpe
Reserved: 19.08.2026 Published: 06.10.2026 Updated: 06.10.2026

A vulnerability have been identified in the management interface of AOS-S that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to gain unauthorized access to the affected system.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Hewlett Packard Enterprise (HPE)
Product AOS-Switch (AOS-S)
Versions Default: affected
  • affected from 16.11.0000 to 16.11.0031 (incl.)

Credits

  • Internal security research (HPE Networking). reporter

References