Junglewise Threat Intelligence

CVE-2026-44863: HPE Aruba Networking AOS SQL injection in management interface

CVE-2026-44863 · Severity: high · CVSS 7.2 · Published 2026-05-12

Technologies: HPE Aruba Networking AOS-10, HPE Aruba Networking AOS-8. Vendors: HPE Aruba Networking.

Executive brief

HPE Aruba Networking AOS-8 and AOS-10, the operating systems used to manage enterprise wireless networks and access points, are affected by a security vulnerability in their management interfaces. An attacker who already has administrative access could use this flaw to run unauthorized commands on the underlying system. This could lead to a complete takeover of the networking equipment, potentially disrupting network operations or allowing further access into the corporate environment.

Technical details

Multiple SQL injection vulnerabilities exist within the underlying service components of HPE Aruba Networking AOS-8 and AOS-10. The flaw is located in the command-line interface (CLI) and management protocol handlers, where user-supplied input is passed unsanitized to backend database queries (CWE-89). An attacker must be authenticated with high-level administrative privileges to reach the vulnerable parameters. Successful exploitation allows the attacker to break out of the restricted management environment and execute arbitrary commands with system-level privileges on the underlying operating system. The vulnerability is tracked as CVE-2026-44863 and has a CVSS v3.1 base score of 7.2.

Affected products

  • HPE Aruba Networking AOS-8
  • HPE Aruba Networking AOS-10

Timeline

  • 2026-05-12: advisory: Initial advisory published by HPE and NVD.

References

Related threats