Junglewise Threat Intelligence

CVE-2026-23820: HPE Aruba AOS command injection in Access Point CLI

CVE-2026-23820 · Severity: high · CVSS 7.2 · Published 2026-05-12

Technologies: HPE Aruba Networking AOS-10, HPE Aruba Networking AOS-8 Instant. Vendors: HPE Aruba Networking.

Executive brief

A security vulnerability exists in the command line interface of certain Aruba wireless access points. An authorized user with administrative privileges could bypass security restrictions to run unauthorized commands on the device's underlying operating system. This could lead to a full compromise of the access point, potentially allowing an attacker to disrupt wireless services or intercept network traffic.

Technical details

An OS command injection vulnerability (CWE-78) exists in the command line interface (CLI) of Aruba Access Points running AOS-10 and AOS-8 Instant. The flaw allows an authenticated remote attacker with high privileges to escape the restricted shell environment. By providing specially crafted input to certain CLI commands, the attacker can execute arbitrary commands with the privileges of the underlying operating system. This can result in a complete compromise of the device's confidentiality, integrity, and availability. The vulnerability is tracked as CVE-2026-23820 and was reported by Hewlett Packard Enterprise.

Affected products

  • HPE Aruba Networking AOS-10
  • HPE Aruba Networking AOS-8 Instant

Timeline

  • 2026-05-12: disclosed: Initial disclosure by HPE/Aruba
  • 2026-05-12: advisory: NVD record published

References

Related threats