Junglewise Threat Intelligence

CVE-2026-44857: HPE Aruba Networking AOS stack overflow in management services

CVE-2026-44857 · Severity: high · CVSS 7.2 · Published 2026-05-12

Technologies: HPE Aruba Networking AOS-10, HPE Aruba Networking AOS-8. Vendors: HPE Aruba Networking.

Executive brief

HPE Aruba Networking AOS-8 and AOS-10 are operating systems used to manage enterprise wireless and wired network infrastructure. A security vulnerability in the management interface could allow an authorized administrator to bypass security controls and take full control of the underlying system. While this requires existing administrative access, it could be used by a malicious insider or a compromised account to gain deeper, persistent access to the network hardware.

Technical details

Multiple stack-based buffer overflow vulnerabilities (CWE-121) exist within the management service components of AOS-8 and AOS-10. These vulnerabilities are reachable via the command-line interface (CLI). An attacker must be authenticated with high (administrative) privileges to exploit the flaw. By sending specially crafted requests to the affected services, an attacker can trigger the overflow to execute arbitrary code with elevated privileges on the underlying operating system. The vulnerability is tracked as CVE-2026-44857 and was reported by HPE.

Affected products

  • HPE Aruba Networking AOS-8
  • HPE Aruba Networking AOS-10

Timeline

  • 2026-05-12: disclosed: Initial disclosure by HPE and NVD publication.
  • 2026-05-13: advisory: CISA-ADP enrichment and CWE-121 association.

References

Related threats