---
id: CVE-2026-76743
title: >-
  A vulnerability have been identified in the management interface of AOS-S that
  could potentially allow an unauthenticated remote attacker to circumvent
  existing authentication controls if certain preconditions outside of the
  attacker's c…
summary: >-
  A vulnerability have been identified in the management interface of AOS-S that
  could potentially allow an unauthenticated remote attacker to circumvent
  existing authentication controls if certain preconditions outside of the
  attacker's c…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: Hewlett Packard Enterprise (HPE)
product: AOS-Switch (AOS-S)
affected:
  - aos-switch_aos-s >= 16.11.0000 <= 16.11.0031
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:17:29.603'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76743'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05156en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T20:16:42.511Z'
---

## Overview

A vulnerability have been identified in the management interface of AOS-S that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to gain unauthorized access to the affected system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
