# HPE Aruba AOS-CX Pre-Auth Admin Password Reset (CVE-2026-23813)

> Critical authentication bypass (CVSS 9.8) in the web-based management interface of HPE Aruba AOS-CX switches allows unauthenticated remote attackers to circumvent authentication controls and reset administrator passwords. Affects 11 CX switch series across 4 firmware branches, enabling full device takeover of enterprise network infrastructure.

- **Published:** 2026-03-17T12:00:00Z
- **Last reviewed:** 2026-03-17T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0240
- **ID:** TL-2026-0240
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-23813

## Description

CVE-2026-23813 is a critical authentication bypass vulnerability in the web-based management interface of HPE Aruba Networking AOS-CX switches. The flaw allows an unauthenticated remote attacker to circumvent existing authentication controls and, in some cases, reset the administrator password of the device, granting full administrative control over the affected switch.

The vulnerability resides in the HTTP/HTTPS management interface and can be exploited remotely with low attack complexity, requiring no authentication or user interaction. The CVSS 3.1 base score of 9.8 reflects the severity: network attack vector, no privileges required, and high impact across confidentiality, integrity, and availability.

Affected hardware spans 11 HPE Aruba CX switch series: CX 4100i, CX 6000, CX 6100, CX 6200, CX 6300, CX 6400, CX 8320, CX 8325, CX 8360, CX 9300, and CX 10000. These switches are widely deployed in enterprise campus and data center environments, making the attack surface significant. Four firmware branches are affected: AOS-CX 10.10.xxxx (10.10.1170 and earlier), 10.13.xxxx (10.13.1160 and earlier), 10.16.xxxx (10.16.1020 and earlier), and 10.17.xxxx (10.17.0001 and earlier).

The vulnerability was discovered by security researcher 'moonv' through the HPE Aruba Networking Bug Bounty Program and disclosed on March 11, 2026 via HPE Security Advisory HPESBNW04848. At the time of disclosure, HPE stated it was not aware of any public exploitation or proof-of-concept code targeting the vulnerability.

Critically, CVE-2026-23813 can be chained with CVE-2026-23814 (CVSS 8.8), an authenticated command injection flaw in the same AOS-CX platform. This creates a devastating attack chain: the authentication bypass provides initial access, and the command injection enables arbitrary command execution on the switch operating system. Together, they enable full remote code execution on enterprise network infrastructure without any prior credentials.

Three additional high-severity vulnerabilities were disclosed alongside CVE-2026-23813: CVE-2026-23815 (CVSS 7.2, high-privilege command injection), CVE-2026-23816 (CVSS 7.2, CLI command injection), and CVE-2026-23817 (CVSS 6.5, open redirect). All are addressed in the same firmware updates.

HPE released patched firmware versions: AOS-CX 10.17.1001, 10.16.1030, 10.13.1161, and 10.10.1180. Organizations unable to immediately patch should isolate management interfaces on dedicated VLANs, restrict access to trusted hosts via Layer 3 ACLs and Control Plane ACLs, disable HTTP/HTTPS management on unnecessary ports, and enable comprehensive logging and monitoring for unauthorized access attempts.

The CWE classification is CWE-287 (Improper Authentication), as identified by CISA-ADP. The vulnerability represents a significant risk to organizations relying on Aruba CX switches for critical network infrastructure, particularly given the low complexity of exploitation and the potential for full device takeover leading to traffic interception, network persistence, and lateral movement.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1556 Modify Authentication Process
- T1078 Valid Accounts
- T1021 Remote Services
- T1046 Network Service Discovery
- T1040 Network Sniffing
- T1059 Command and Scripting Interpreter
- T1498 Network Denial of Service
- T1595 Active Scanning
- T1070 Indicator Removal
- T1071 Application Layer Protocol

## Sources

- [HPE Security Advisory HPESBNW04848 — AOS-CX Authentication Bypass](https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04848en_us)
- [NVD — CVE-2026-23813](https://nvd.nist.gov/vuln/detail/CVE-2026-23813)
- [GitHub Advisory Database — GHSA-37q7-686v-7f32](https://github.com/advisories/GHSA-37q7-686v-7f32)
- [CyCognito — Emerging Threat: HPE AOS-CX Pre-Auth RCE Chain (CVE-2026-23813 / CVE-2026-23814)](https://www.cycognito.com/blog/what-is-cve-2026-23813-cve-2026-23814/)
- [SecurityWeek — Critical HPE AOS-CX Vulnerability Allows Admin Password Resets](https://www.securityweek.com/critical-hpe-aos-cx-vulnerability-allows-admin-password-resets/)
- [BleepingComputer — HPE Warns of Critical AOS-CX Flaw Allowing Admin Password Resets](https://www.bleepingcomputer.com/news/security/hpe-warns-of-critical-aos-cx-flaw-allowing-admin-password-resets/)
- [Security Online — Critical 9.8 CVSS Bypass Unearthed in HPE Aruba AOS-CX Switches](https://securityonline.info/critical-9-8-cvss-bypass-unearthed-in-hpe-aruba-aos-cx-switches/)
- [Security Affairs — HPE Fixes Critical Authentication Bypass in Aruba AOS-CX](https://securityaffairs.com/189278/security/hewlett-packard-enterprise-fixes-critical-authentication-bypass-in-aruba-aos-cx.html)
- [Field Effect — Critical Authentication Bypass in Aruba AOS-CX Impacts CX-Series Switches](https://fieldeffect.com/blog/critical-authentication-bypass-in-aruba-aos-cx-impacts-cx-series-switches)
- [SC Media — HPE Aruba AOS-CX Vulnerabilities Addressed Including Critical Password Reset Flaw](https://www.scworld.com/brief/hpe-aruba-aos-cx-vulnerabilities-addressed-including-critical-password-reset-flaw)
- [TechRadar — HPE Warns of Dangerous Security Flaw Allowing Aruba OS Password Resets](https://www.techradar.com/pro/security/hpe-warns-of-dangerous-security-flaw-which-could-allow-aruba-os-password-resets)
- [INCIBE-CERT — CVE-2026-23813](https://www.incibe.es/incibe-cert/alerta-temprana/vulnerabilidades/cve-2026-23813)
- [CERT-IN CIVN-2026-0137 — Multiple Vulnerabilities in HPE Aruba Networking AOS-CX](https://teamwin.in/civn-2026-0137-multiple-vulnerabilities-in-hpe-aruba-networking-aos-cx/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0240
