Junglewise Threat Intelligence

CVE-2026-44859: Aruba AOS stack overflow in management CLI

CVE-2026-44859 · Severity: high · CVSS 7.2 · Published 2026-05-12

Technologies: Aruba (HPE) AOS-8, Aruba (HPE) AOS-10.

Executive brief

A security vulnerability has been identified in the Aruba AOS-8 and AOS-10 operating systems, which are used to manage enterprise networking hardware. An authorized administrator could potentially bypass security controls to run unauthorized commands on the underlying system. If exploited, this could allow an attacker to take full control of the networking device, potentially leading to data interception or network disruption.

Technical details

Multiple stack-based buffer overflow vulnerabilities (CWE-121) exist within the management service components of Aruba AOS-8 and AOS-10. The flaw is accessible via the Command-Line Interface (CLI) and is triggered when the system processes specially crafted requests. An attacker must be authenticated with high-level administrative privileges to exploit this vulnerability. Successful exploitation allows for arbitrary code execution with elevated privileges on the underlying operating system. The vulnerability is reachable over the network (AV:N) but requires prior administrative access (PR:H).

Affected products

  • Aruba (HPE) AOS-8
  • Aruba (HPE) AOS-10

Timeline

  • 2026-05-12: disclosed: Initial disclosure by HPE/Aruba
  • 2026-05-12: advisory: NVD record published

References