Junglewise Threat Intelligence

CVE-2026-44870: HPE Aruba AOS command injection in CLI service via PAPI protocol

CVE-2026-44870 · Severity: high · CVSS 7.2 · Published 2026-05-12

Technologies: HPE Aruba Networking AOS-10, HPE Aruba Networking AOS-8. Vendors: HPE Aruba Networking.

Executive brief

A vulnerability exists in the operating systems used by HPE Aruba networking devices, specifically within the command line interface service. An authorized user with high-level administrative privileges could exploit this flaw to run unauthorized commands on the device's underlying operating system. This could lead to a complete takeover of the networking equipment, potentially compromising the security and availability of the corporate network.

Technical details

Command injection vulnerabilities (CWE-77) exist in the Command Line Interface (CLI) service of HPE Aruba AOS-8 and AOS-10. The flaw is accessible via the Process Application Programming Interface (PAPI) protocol. An attacker requires network reachability and high-level administrative privileges (PR:H) to exploit the vulnerability. Successful exploitation allows for arbitrary command execution on the underlying Linux-based operating system with the privileges of the CLI service. HPE has addressed these issues in updated versions of AOS; users are advised to consult the HPE support portal for specific patched firmware versions.

Affected products

  • HPE Aruba Networking AOS-8
  • HPE Aruba Networking AOS-10

Timeline

  • 2026-05-12: disclosed: Initial disclosure by HPE
  • 2026-05-12: advisory: NVD publication date

References

Related threats