Junglewise Threat Intelligence

CVE-2026-44866: HPE Aruba Networking AOS command injection in web management interface

CVE-2026-44866 · Severity: high · CVSS 7.2 · Published 2026-05-12

Technologies: HPE Aruba Networking AOS-10, HPE Aruba Networking AOS-8. Vendors: HPE Aruba Networking.

Executive brief

A security vulnerability exists in the web management interface of HPE Aruba Networking AOS-8 and AOS-10 operating systems, which are used to manage enterprise network infrastructure. An authorized administrator could exploit this flaw to run unauthorized commands on the underlying system. This could lead to a complete takeover of the networking equipment, potentially allowing an attacker to intercept traffic or disrupt network operations.

Technical details

Command injection vulnerabilities (CWE-77) exist within the web-based management interface of HPE Aruba Networking AOS-8 and AOS-10. The flaw is rooted in the improper neutralization of special elements used in commands within the web UI. An attacker with high-privileged administrative credentials can exploit this over the network without user interaction. Successful exploitation allows for arbitrary command execution on the underlying Linux-based operating system, potentially leading to full system compromise. Users are advised to refer to the HPE security advisory for specific patched firmware versions.

Affected products

  • HPE Aruba Networking AOS-8
  • HPE Aruba Networking AOS-10

Timeline

  • 2026-05-12: disclosed: Initial disclosure by HPE
  • 2026-05-12: advisory: NVD publication date

References

Related threats