Junglewise Threat Intelligence

CVE-2026-44855: HPE Aruba Networking AOS stack overflow in management CLI

CVE-2026-44855 · Severity: high · CVSS 7.2 · Published 2026-05-12

Technologies: HPE Aruba Networking AOS-10, HPE Aruba Networking AOS-8. Vendors: HPE Aruba Networking.

Executive brief

HPE Aruba Networking AOS-8 and AOS-10 operating systems, which power enterprise network controllers and access points, are affected by security vulnerabilities in their management interface. An attacker who already has administrative access could use these flaws to take full control of the underlying operating system. This could lead to a complete compromise of the networking hardware and the data passing through it.

Technical details

Multiple stack-based buffer overflow vulnerabilities (CWE-121) exist within the management service components of AOS-8 and AOS-10. These vulnerabilities are accessible via the command-line interface (CLI). An authenticated attacker with high privileges (administrative) can exploit these flaws by sending specially crafted requests to the affected services. Successful exploitation allows for arbitrary code execution with elevated privileges on the underlying Linux-based operating system. The vulnerability is reachable over the network, though it requires valid administrative credentials.

Affected products

  • HPE Aruba Networking AOS-8
  • HPE Aruba Networking AOS-10

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats