Junglewise Threat Intelligence

CVE-2026-44860: HPE Aruba Networking AOS SQL injection in CLI and management protocol

CVE-2026-44860 · Severity: high · CVSS 7.2 · Published 2026-05-12

Technologies: HPE Aruba Networking AOS-10, HPE Aruba Networking AOS-8. Vendors: HPE Aruba Networking.

Executive brief

HPE Aruba Networking AOS-8 and AOS-10, the operating systems used to manage enterprise wireless networks and mobility controllers, are affected by a security vulnerability in their management interfaces. An attacker who already has administrative access could use specially crafted commands to bypass security controls and gain full control over the underlying operating system. This could lead to a complete compromise of the networking hardware, allowing the attacker to disrupt operations or access sensitive configuration data.

Technical details

Multiple SQL injection vulnerabilities exist within the service components of HPE Aruba Networking AOS-8 and AOS-10. The flaw is located in the command-line interface (CLI) and management protocol handlers, where user-supplied input is passed unsanitized to backend database queries (CWE-89). An authenticated attacker with high privileges (administrative access) can exploit this over the network by injecting malicious SQL syntax into specific parameters. Successful exploitation allows the attacker to break out of the restricted management environment and execute arbitrary commands with system-level privileges on the underlying operating system.

Affected products

  • HPE Aruba Networking AOS-8
  • HPE Aruba Networking AOS-10

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats