Junglewise Threat Intelligence

CVE-2026-44862: HPE Aruba Networking AOS SQL injection in CLI and management protocol

CVE-2026-44862 · Severity: high · CVSS 7.2 · Published 2026-05-12

Technologies: HPE Aruba Networking AOS-10, HPE Aruba Networking AOS-8. Vendors: HPE Aruba Networking.

Executive brief

A security vulnerability has been identified in the operating systems used by Aruba networking devices, which are responsible for managing enterprise wireless and wired networks. An attacker with administrative access could use the management interface to run unauthorized commands on the device's underlying system. This could lead to a complete takeover of the networking equipment, potentially disrupting network operations or allowing further access into the corporate environment.

Technical details

SQL injection vulnerabilities exist within multiple service components of HPE Aruba Networking AOS-8 and AOS-10. The flaw is located in the command-line interface (CLI) and management protocol handlers, where user-supplied parameters are passed to backend database queries without sufficient sanitization. An authenticated attacker with high privileges (administrative access) can exploit this over the network by submitting specially crafted input. Successful exploitation results in a breakout from the restricted management environment, allowing the execution of arbitrary commands with the privileges of the underlying operating system.

Affected products

  • HPE Aruba Networking AOS-8
  • HPE Aruba Networking AOS-10

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats