Junglewise Threat Intelligence

CVE-2026-44872: HPE ArubaOS command injection in web-based management interface

CVE-2026-44872 · Severity: high · CVSS 7.2 · Published 2026-05-12

Vendors: HPE Aruba Networking.

Executive brief

A security vulnerability has been identified in the web management interface of HPE Aruba networking devices. This interface is used by administrators to configure and monitor network hardware. If exploited, an authorized user with high-level privileges could bypass security controls to place unauthorized files on the device, potentially leading to full system compromise or persistent access.

Technical details

A command injection vulnerability (CWE-77) exists in the web-based management interface of HPE ArubaOS (AOS-8 and AOS-10). The flaw stems from improper neutralization of special elements within the management console, allowing an attacker to execute system-level commands. Exploitation requires network access to the management interface and high-level administrative privileges (PR:H). A successful attack allows for arbitrary file writes to the underlying filesystem, which can lead to complete compromise of the device's confidentiality, integrity, and availability. Patches have been released for various branches, including 8.10.0.22, 8.12.0.7, 8.13.1.2, 10.4.1.11, and 10.7.2.3.

Affected products

  • HPE Aruba Networking ArubaOS (AOS-8) 6.5.4.0 to 8.10.0.21, 8.11.0.0 to 8.12.0.6, 8.13.0.0 to 8.13.1.1
  • HPE Aruba Networking ArubaOS (AOS-10) 10.4.0.0 to 10.4.1.10, 10.5.0.0 to 10.7.2.2
  • HPE Aruba Networking SD-WAN 8.6.0.4-2.2.0.0 to 8.6.0.4-2.2.0.7, 8.7.0.0-2.3.0.0 to 8.7.0.0-2.3.0.9

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References