Junglewise Threat Intelligence

CVE-2026-44865: HPE Aruba Networking AOS command injection in web management interface

CVE-2026-44865 · Severity: high · CVSS 7.2 · Published 2026-05-12

Technologies: HPE Aruba Networking AOS-10, HPE Aruba Networking AOS-8. Vendors: HPE Aruba Networking.

Executive brief

A vulnerability exists in the web management interface of HPE Aruba Networking AOS-8 and AOS-10 operating systems, which are used to manage enterprise network infrastructure. An authorized administrator could exploit this flaw to run unauthorized commands on the underlying system. This could lead to a complete takeover of the networking device, potentially disrupting network operations or allowing access to sensitive traffic.

Technical details

Command injection vulnerabilities (CWE-77) exist within the web-based management interface of HPE Aruba Networking AOS-8 and AOS-10. The flaw stems from improper neutralization of special elements used in a command. An attacker with high-privileged administrative credentials can exploit this over the network without user interaction. Successful exploitation allows for arbitrary command execution on the underlying operating system with the privileges of the web service, potentially leading to full system compromise. The vulnerability was reported by Hewlett Packard Enterprise (HPE).

Affected products

  • HPE Aruba Networking AOS-8
  • HPE Aruba Networking AOS-10

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats