Junglewise Threat Intelligence

CVE-2026-44858: HPE Aruba Networking AOS stack overflow in management CLI

CVE-2026-44858 · Severity: high · CVSS 7.2 · Published 2026-05-12

Technologies: HPE Aruba Networking AOS-10, HPE Aruba Networking AOS-8. Vendors: HPE Aruba Networking.

Executive brief

HPE Aruba Networking AOS-8 and AOS-10 operating systems, which manage enterprise wireless and wired networks, are affected by security flaws in their management interface. An attacker who already has administrative access could use these flaws to take full control of the underlying operating system. This could lead to a complete compromise of the networking hardware and the data passing through it.

Technical details

Multiple stack-based buffer overflow vulnerabilities (CWE-121) exist within the management service components of HPE Aruba Networking AOS-8 and AOS-10. The vulnerability is reachable via the command-line interface (CLI). An attacker must be authenticated with high privileges (administrative) to perform the attack. By sending specially crafted requests to the affected management services, the attacker can trigger the overflow to achieve arbitrary code execution with elevated privileges on the underlying Linux-based operating system. The CVSS score of 7.2 reflects that while the impact is critical, the requirement for administrative credentials lowers the overall risk profile.

Affected products

  • HPE Aruba Networking AOS-8
  • HPE Aruba Networking AOS-10

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats