CVE-2026-23813 | Authentication Bypass in Web Interface allows Unauthenticated Admin Password Reset
A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.
Conclusion & alert: CVE-2026-23813 is rated Moderate Risk (45.5/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.06%).Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2026-23813
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).