CVE-2026-23819

HIGH

Error in SSID Processing allows Stored XSS in Web Management Interface

Title source: cna
STIX 2.1

Description

A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network. Successful exploitation could allow an attacker to compromise user data and potentially manipulate device configuration settings.

Scores

CVSS v3 8.8
EPSS 0.0027
EPSS Percentile 18.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (6)
Hewlett Packard Enterprise (HPE)/ArubaOS (AOS) 10.4.0.0 - 10.4.1.10
Hewlett Packard Enterprise (HPE)/ArubaOS (AOS) 10.7.0.0 - 10.7.2.2
Hewlett Packard Enterprise (HPE)/ArubaOS (AOS) 10.8.0.0
Hewlett Packard Enterprise (HPE)/ArubaOS (AOS) 8.10.0.0 - 8.10.0.21
Hewlett Packard Enterprise (HPE)/ArubaOS (AOS) 8.12.0.0 - 8.12.0.6
Hewlett Packard Enterprise (HPE)/ArubaOS (AOS) 8.13.0.0 - 8.13.1.1
Published May 12, 2026
Tracked Since May 13, 2026