Description
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Successful exploitation could allow the attacker to execute arbitrary code with elevated privileges on the underlying operating system.
Published: 2026-05-12
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack‑based buffer overflow that can be triggered when an authenticated user with administrative privileges sends specially crafted requests through the command‑line interface of Hewlett Packard Enterprise Aruba Networking Wireless Operating System versions AOS‑8 or AOS‑10. The overflow occurs in multiple underlying management service components, allowing an attacker to inject and execute arbitrary code with the privileges of those services. The result is that the attacker can run code with elevated privileges on the underlying host operating system, effectively taking full control of the device. This is a classic example of a stack-based buffer overflow (CWE‑121).

Affected Systems

AOS‑8 and AOS‑10 operating systems from Hewlett Packard Enterprise Aruba are affected. All components that process CLI requests in these versions are susceptible, so administrators who have command‑line or service access are at risk.

Risk and Exploitability

The CVSS score of 7.2 indicates a high‑severity vulnerability, and the EPSS score of less than 1% shows a currently low but non‑zero probability of exploitation. The vulnerability is not listed in CISA KEV, but once an attacker obtains or compromises legitimate administrative credentials, the flaw can be triggered remotely via the CLI, granting complete OS‑level takeover. This grants the attacker full confidentiality, integrity, and availability control over the affected device.

Generated by OpenCVE AI on May 13, 2026 at 22:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the HPE Aruba firmware to the latest version that includes the stack buffer overflow fix for AOS‑8 and AOS‑10.
  • Restrict command‑line interface access to trusted administrators and enforce multi‑factor authentication to reduce credential compromise risk.
  • Segment Aruba device traffic into isolated network segments or VLANs to limit the blast radius if a device is compromised.

Generated by OpenCVE AI on May 13, 2026 at 22:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 14 May 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks arubaos
Arubanetworks sd-wan
CPEs cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks arubaos
Arubanetworks sd-wan

Wed, 13 May 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-120

Wed, 13 May 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 13 May 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Hpe
Hpe arubaos
Vendors & Products Hpe
Hpe arubaos

Tue, 12 May 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-120

Tue, 12 May 2026 19:30:00 +0000

Type Values Removed Values Added
Description Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Successful exploitation could allow the attacker to execute arbitrary code with elevated privileges on the underlying operating system.
Title Authenticated Stack-Based Buffer Overflow in PAPI Services
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-05-13T17:50:31.513Z

Reserved: 2026-05-07T21:29:03.734Z

Link: CVE-2026-44856

cve-icon Vulnrichment

Updated: 2026-05-13T17:50:26.267Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-12T20:16:44.217

Modified: 2026-05-14T18:42:12.123

Link: CVE-2026-44856

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T22:45:06Z

Weaknesses