CVE-2026-73751
Received Received - Intake

Authenticated Command Injection in HPE Integrated Lights-Out

Vulnerability report for CVE-2026-73751, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Hewlett Packard Enterprise (HPE)

Description

An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a command injection vulnerability where an authenticated user with low privileges can send specially crafted input through the web management interface. This input is then executed as arbitrary commands on the underlying operating system.

Impact Analysis

An attacker could gain full control over the affected system, allowing them to install malware, steal data, disrupt operations, or pivot to other systems in the network. The high CVSS score indicates significant risk.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations may face fines, legal action, and reputational damage.

Mitigation Strategies

Immediately restrict low-privileged user access to the web-based management interface. Apply vendor patches or updates if available. Monitor network traffic for unusual command execution patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73751. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart