Executive brief
HPE Aruba Networking AOS-8 and AOS-10, the operating systems used to manage enterprise wireless networks and access points, are affected by a security vulnerability in their management interfaces. An attacker who already has administrative access could use this flaw to run unauthorized commands on the underlying system. This could lead to a complete takeover of the networking equipment, potentially disrupting network operations or allowing further access into the corporate environment.
Technical details
Multiple SQL injection vulnerabilities exist within the underlying service components of HPE Aruba Networking AOS-8 and AOS-10. The flaw is located in the command-line interface (CLI) and management protocol handlers, where user-supplied input is passed unsanitized to backend database queries (CWE-89). An attacker must be authenticated with high-level administrative privileges to reach the vulnerable parameters. Successful exploitation allows the attacker to break out of the restricted management environment and execute arbitrary commands with system-level privileges on the underlying operating system. The vulnerability is tracked as CVE-2026-44863 and has a CVSS v3.1 base score of 7.2.
Affected products
- HPE Aruba Networking AOS-8
- HPE Aruba Networking AOS-10
Timeline
- 2026-05-12: advisory: Initial advisory published by HPE and NVD.