Junglewise Threat Intelligence

CVE-2026-44873: HPE AOS-8 insufficient session expiration after account revocation

CVE-2026-44873 · Severity: medium · CVSS 5.4 · Published 2026-05-12

Vendors: Hpe.

Executive brief

A vulnerability in the AOS-8 operating system, used in Aruba networking hardware, allows users to maintain access to the network even after their accounts have been disabled by an administrator. Because active sessions are not immediately terminated when an account is revoked, an unauthorized individual or a former employee could continue to access internal resources until their session naturally expires. This could lead to unauthorized data access or persistent presence on the network by individuals who should no longer have permission.

Technical details

A session management vulnerability exists in HPE AOS-8 due to insufficient session expiration (CWE-613). The root cause is the system's failure to invalidate active session tokens or state when a user's credentials are revoked or their account is administratively disabled. An attacker who has already established a valid session—or an attacker using compromised credentials to establish one before the account is disabled—can maintain network access and perform authorized actions until the session naturally times out. The attack requires low privileges (an authenticated session) and is reachable over the network with no user interaction required.

Affected products

  • HPE AOS-8

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References