Description
Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.
Published: 2026-05-12
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a command injection flaw in the command line interface (CLI) of HPE Aruba OS 8 and 10 accessed via the PAPI protocol. An authenticated attacker can supply arbitrary command strings that are executed by the underlying operating system, enabling remote code execution.

Affected Systems

HPE Aruba Networking Wireless Operating System (AOS) versions AOS‑8 and AOS‑10 are affected. The entry point for the flaw is the CLI service accessed through the PAPI protocol; no other vendors or products are listed.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity, but the EPSS score of less than 1 % suggests a very low likelihood of active exploitation in the wild. The flaw is not included in the CISA KEV catalog. Exploitation requires authenticated remote access to the CLI, i.e., a compromised or stolen credential is a prerequisite. Once access is gained, the attacker can inject commands to be executed with the privileges of the CLI user.

Generated by OpenCVE AI on May 13, 2026 at 20:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE Aruba OS firmware or patch that addresses the CLI command injection flaw.
  • Restrict PAPI traffic by configuring firewall rules or disabling the CLI service on devices that do not require remote command access.
  • Enforce least privilege for CLI accounts by using strong, regularly rotated passwords and enabling two-factor authentication where possible.
  • Enable comprehensive logging for CLI activity and review logs for unexpected commands or authentication attempts.

Generated by OpenCVE AI on May 13, 2026 at 20:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 14 May 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks arubaos
Arubanetworks sd-wan
CPEs cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks arubaos
Arubanetworks sd-wan

Thu, 14 May 2026 05:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 13 May 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Wed, 13 May 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77

Wed, 13 May 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Hpe
Hpe arubaos
Vendors & Products Hpe
Hpe arubaos

Tue, 12 May 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Tue, 12 May 2026 21:30:00 +0000

Type Values Removed Values Added
Description Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.
Title Authenticated Command Injection Vulnerabilities in Command Line Interface (CLI) Service Accessed by PAPI Protocol of AOS-8 and AOS-10 Operating Systems
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-05-14T03:56:13.003Z

Reserved: 2026-05-07T21:29:22.242Z

Link: CVE-2026-44871

cve-icon Vulnrichment

Updated: 2026-05-13T14:23:57.584Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-12T22:16:37.820

Modified: 2026-05-14T14:29:18.143

Link: CVE-2026-44871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T20:45:04Z

Weaknesses