Junglewise Threat Intelligence

CVE-2026-44867: HPE Aruba AOS command injection in web management interface

CVE-2026-44867 · Severity: high · CVSS 7.2 · Published 2026-05-12

Technologies: HPE Aruba Networking AOS-10, HPE Aruba Networking AOS-8. Vendors: HPE Aruba Networking.

Executive brief

A vulnerability exists in the web management interface of HPE Aruba Networking operating systems used to manage enterprise network infrastructure. An authorized administrator could exploit this flaw to run unauthorized commands on the underlying system. This could lead to a complete takeover of the networking device, potentially disrupting network operations or allowing access to sensitive traffic.

Technical details

Command injection vulnerabilities reside within the web-based management interface of HPE Aruba AOS-8 and AOS-10. The flaw is triggered by insufficient sanitization of user-supplied input passed to system shells. An attacker with high-privileged (PR:H) network access to the management console can execute arbitrary commands with the privileges of the underlying operating system. This could result in full system compromise, data exfiltration, or persistent access. The vulnerability is tracked as CVE-2026-44867 with a CVSS base score of 7.2.

Affected products

  • HPE Aruba Networking AOS-8
  • HPE Aruba Networking AOS-10

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats