Junglewise Threat Intelligence

CVE-2026-44864: Aruba AOS SQL injection in CLI and management protocol

CVE-2026-44864 · Severity: high · CVSS 7.2 · Published 2026-05-12

Technologies: Aruba Networks (HPE) AOS-8, Aruba Networks (HPE) AOS-10.

Executive brief

Aruba AOS-8 and AOS-10 are operating systems used to manage enterprise network infrastructure such as wireless controllers and access points. A security flaw in the management interface allows an administrator to run unauthorized commands on the underlying system. While this requires existing administrative access, it could allow a malicious insider or a compromised admin account to take full control of the networking hardware and disrupt operations.

Technical details

Multiple SQL injection vulnerabilities exist within the service components of Aruba AOS-8 and AOS-10. These flaws are accessible via the Command-Line Interface (CLI) and management protocols. The root cause is the failure to sanitize input parameters before passing them to backend database queries (CWE-89). An attacker must have authenticated administrative privileges to exploit these vulnerabilities. Successful exploitation allows for a pivot from SQL injection to arbitrary command execution on the underlying operating system, leading to a full compromise of the device's confidentiality, integrity, and availability.

Affected products

  • Aruba Networks (HPE) AOS-8
  • Aruba Networks (HPE) AOS-10

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References