HPE Aruba AOS-CX Pre-Auth Admin Password Reset (CVE-2026-23813) — Threadlinqs Intelligence
As of 2026-05-30, HPE Aruba AOS-CX Pre-Auth Admin Password Reset (CVE-2026-23813) is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-0240 · Severity: CRITICAL · CVSS: 9.8 · Status: PATCHED · Category: VULNERABILITY
Attribution: N/A · UNKNOWN
Critical authentication bypass (CVSS 9.8) in the web-based management interface of HPE Aruba AOS-CX switches allows unauthenticated remote attackers to circumvent authentication controls and reset
CVE-2026-23813 is a critical authentication bypass vulnerability in the web-based management interface of HPE Aruba Networking AOS-CX switches. The flaw allows an unauthenticated remote attacker to circumvent existing authentication controls and, in some cases, reset the administrator password of the device, granting full administrative control over the affected switch.
The vulnerability resides in the HTTP/HTTPS management interface and can be exploited remotely with low attack complexity, requiring no authentication or user interaction. The CVSS 3.1 base score of 9.8 reflects the severity: network attack vector, no privileges required, and high impact across confidentiality, integrity, and availability.
Affected hardware spans 11 HPE Aruba CX switch series: CX 4100i, CX 6000, CX 6100, CX 6200, CX 6300, CX 6400, CX 8320, CX 8325, CX 8360, CX 9300, and CX 10000. These switches are widely deployed in enterprise campus and data center environments, making the attack surface significant. Four firmware branches are affected: AOS-CX 10.10.xxxx (10.10.1170 and earlier), 10.13.xxxx (10.13.1160 and earlier), 10.16.xxxx (10.16.1020 and earlier), and 10.17.xxxx (10.17.0001 and earlier).
The vulnerability was discovered by security researcher 'moonv' through the HPE Aruba Networking Bug Bounty Program and disclosed on March 11, 2026 via HPE Security Advisory HPESBNW04848. At the time of disclosure, HPE stated it was not aware of any public exploitation or proof-of-concept code targeting the vulnerability.
Critically, CVE-2026-23813 can be chained with CVE-2026-23814 (CVSS 8.8), an authenticated command injection flaw in the same AOS-CX platform. This creates a devastating attack chain: the authentication bypass provides initial access, and the command injection enables arbitrary command execution on the switch operating system. Together, they enable full remote code execution on enterprise network infrastructure without any prior credentials.
Three additional high-severity vulnerabilities were disclosed alongside CVE-2026-23813: CVE-2026-23815 (CVSS 7.2, high-privilege command injection), CVE-2026-23816 (CVSS 7.2, CLI command injection), and CVE-2026-23817 (CVSS 6.5, open redirect). All are addressed in the same firmware updates.
HPE released patched firmware versions: AOS-CX 10.17.1001, 10.16.1030, 10.13.1161, and 10.10.1180. Organizations unable to immediately patch should isolate management interfaces on dedicated VLANs, restrict access to trusted hosts via Layer 3 ACLs and Control Plane ACLs, disable HTTP/HTTPS management on unnecessary ports, and enable comprehensive logging and monitoring for unauthorized access attempts.
The CWE classification is CWE-287 (Improper Authentication), as identified by CISA-ADP. The vulnerability represents a significant risk to organizations relying on Aruba CX switches for critical network infrastructure, particularly given the low complexity of exploitation and the potential for full device takeover leading to traffic interception, network persistence, and lateral movement.
Target sectors: enterprise, government, financial, healthcare, education, telecommunications, manufacturing, energy, retail, technology
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-23813, T1190, T1556, T1078, T1078, T1078, T1021, T1046, T1040, T1059, T1498