Junglewise Threat Intelligence

CVE-2026-44868: HPE Aruba Networking AOS command injection in web management interface

CVE-2026-44868 · Severity: high · CVSS 7.2 · Published 2026-05-12

Technologies: HPE Aruba Networking AOS-10, HPE Aruba Networking AOS-8. Vendors: HPE Aruba Networking.

Executive brief

A vulnerability exists in the web management interface of HPE Aruba Networking AOS-8 and AOS-10 operating systems, which are used to manage enterprise network infrastructure. An authorized administrator could exploit this flaw to run unauthorized commands on the underlying system. This could lead to a complete takeover of the networking device, potentially resulting in network outages or unauthorized access to sensitive data.

Technical details

Command injection vulnerabilities exist within the web-based management interface of HPE Aruba Networking AOS-8 and AOS-10. The flaw is reachable over the network and requires high-privileged authentication (PR:H) to exploit. By submitting specially crafted input to the management interface, an attacker can bypass input validation to execute arbitrary system-level commands. This grants the attacker full control over the underlying operating system with the privileges of the web service. HPE has released an advisory (hpesbnw05048en_us) detailing the affected versions and necessary updates.

Affected products

  • HPE Aruba Networking AOS-8
  • HPE Aruba Networking AOS-10

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats