Junglewise Threat Intelligence

CVE-2026-23819: HPE Aruba AOS Cross-Site Scripting in Web Management Interface

CVE-2026-23819 · Severity: high · CVSS 8.8 · Published 2026-05-12

Technologies: HPE Aruba Networking AOS-10, HPE Aruba Networking AOS-8 Instant. Vendors: HPE Aruba Networking.

Executive brief

A security vulnerability exists in the web management interface of certain Aruba wireless access points. An attacker on the same local network could trick a user into executing malicious code in their web browser. This could lead to the theft of sensitive user data or unauthorized changes to the wireless network's configuration.

Technical details

A vulnerability classified as Improper Neutralization of Input During Web Page Generation (CWE-79), or Cross-Site Scripting (XSS), exists in the web-based management interface of Aruba Access Points. The flaw affects devices running AOS-10 and AOS-8 Instant. An unauthenticated attacker located on the same local network (Adjacent vector) can exploit this by inducing a user to interact with a malicious link or page. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking, data exfiltration, or unauthorized modification of device settings. The CVSS score of 8.8 reflects the high impact on confidentiality, integrity, and availability due to the 'Scope: Changed' (S:C) metric common in XSS attacks.

Affected products

  • HPE Aruba Networking AOS-10
  • HPE Aruba Networking AOS-8 Instant

Timeline

  • 2026-05-12: advisory: Initial disclosure by HPE/Aruba

References

Related threats