Junglewise Threat Intelligence

CVE-2026-44854: HPE Aruba Networking AOS command injection in web management interface

CVE-2026-44854 · Severity: high · CVSS 7.2 · Published 2026-05-12

Technologies: HPE Aruba Networking AOS-10, HPE Aruba Networking AOS-8. Vendors: HPE Aruba Networking.

Executive brief

A security vulnerability exists in the web management interface of HPE Aruba Networking operating systems (AOS-8 and AOS-10). An authorized administrator could exploit this flaw to upload malicious files and take full control of the underlying system. This could lead to a complete compromise of the networking hardware, potentially allowing an attacker to intercept traffic or disrupt network operations.

Technical details

Command injection vulnerabilities (CWE-77) exist within the web-based management interface of HPE Aruba Networking AOS-8 and AOS-10. The flaw is rooted in improper neutralization of special elements used in commands, which allows an authenticated remote attacker with high privileges (PR:H) to upload arbitrary files to the underlying operating system. Successful exploitation can lead to remote code execution (RCE) with elevated privileges. The attack is reachable over the network without user interaction. Users are advised to refer to HPE advisory hpesbnw05048en_us for specific patched version details.

Affected products

  • HPE Aruba Networking AOS-8
  • HPE Aruba Networking AOS-10

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats