CVE-2026-23813: Authentication Bypass in Web Interface allows Unauthenticated Admin Password Reset
Published Mar 11, 2026
·Updated
A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.
Affected Software
1 affected component
Aruba AOS-CX
Event History
Mar 10, 2026
News Published
via BleepingComputer·05:30 PM
News Published
via BleepingComputer·05:32 PM
Mar 11, 2026
CVE Published
via MITRE·03:08 AM
Data Sourced
via MITRE·03:08 AM
DescriptionSeverity
Data Sourced
via NVD·04:17 AM
DescriptionSeverityWeakness