CVE-2026-44866

HIGH

Authenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10

Title source: cna
STIX 2.1

Description

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

Scores

CVSS v3 7.2
EPSS 0.0019
EPSS Percentile 40.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (8)
arubanetworks/arubaos 6.5.4.0 - 8.10.0.22
arubanetworks/sd-wan 8.6.0.4-2.2.0.0 - 8.6.0.4-2.2.0.7
Hewlett Packard Enterprise (HPE)/HPE Aruba Networking Wireless Operating System (AOS) 10.4.0.0 - 10.4.1.10
Hewlett Packard Enterprise (HPE)/HPE Aruba Networking Wireless Operating System (AOS) 10.7.0.0 - 10.7.2.2
Hewlett Packard Enterprise (HPE)/HPE Aruba Networking Wireless Operating System (AOS) 10.8.0.0
Hewlett Packard Enterprise (HPE)/HPE Aruba Networking Wireless Operating System (AOS) 8.10.0.0 - 8.10.0.21
Hewlett Packard Enterprise (HPE)/HPE Aruba Networking Wireless Operating System (AOS) 8.12.0.0 - 8.12.0.6
Hewlett Packard Enterprise (HPE)/HPE Aruba Networking Wireless Operating System (AOS) 8.13.0.0 - 8.13.1.1
Published May 12, 2026
Tracked Since May 13, 2026