Junglewise Threat Intelligence

CVE-2026-44853: HPE Aruba Networking AOS command injection in web management interface

CVE-2026-44853 · Severity: high · CVSS 7.2 · Published 2026-05-12

Technologies: HPE Aruba Networking AOS-10, HPE Aruba Networking AOS-8. Vendors: HPE Aruba Networking.

Executive brief

A vulnerability exists in the web management interface of HPE Aruba Networking AOS-8 and AOS-10 operating systems, which are used to manage enterprise network infrastructure. An authorized administrator could exploit this flaw to upload malicious files and execute commands on the underlying system. This could lead to a complete takeover of the networking device, potentially allowing an attacker to intercept traffic or disrupt network operations.

Technical details

Command injection vulnerabilities (CWE-77) exist within the web-based management interface of HPE Aruba Networking AOS-8 and AOS-10. The flaw stems from improper neutralization of special elements used in commands within the management UI. An attacker with high-privileged credentials (PR:H) can exploit this over the network without user interaction to upload arbitrary files to the underlying operating system. Successful exploitation allows for remote code execution (RCE) with elevated privileges, granting full control over the affected networking hardware.

Affected products

  • HPE Aruba Networking AOS-8
  • HPE Aruba Networking AOS-10

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats