High [CVE-2026-23819] AOS-10: vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network
This high-severity HPE Aruba Networking advisory covers CVE-2026-23819 affecting AOS-10, AOS-8.
Android app · Google Play
Monitor future HPE Aruba Networking CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network.
Successful exploitation could allow an attacker to compromise user data and potentially manipulate device configuration settings.
- AOS-10 10.8.0.0
- AOS-10 10.7.0.0 through 10.7.2.2
- AOS-10 10.4.0.0 through 10.4.1.10
- Instant AP 8.13.0.0 through 8.13.1.1
- Instant AP 8.12.0.0 through 8.12.0.6
- Instant AP 8.10.0.0 through 8.10.0.21
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
- AOS-10 10.8.0.1 or above
- AOS-10 10.7.2.3 or above
- AOS-10 10.4.1.11 or above
- Instant AP 8.13.1.2 or above
- Instant AP 8.12.0.7 or above
- Instant AP 8.10.0.22 or above
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
Mitigation checklist
- Upgrade affected HPE Aruba Networking devices to an applicable fixed release: AOS-10 10.8.0.1 or above, AOS-10 10.7.2.3 or above, AOS-10 10.4.1.11 or above, Instant AP 8.13.1.2 or above, Instant AP 8.12.0.7 or above, Instant AP 8.10.0.22 or above.
- To address the vulnerabilities described above in the affected software branches, upgrade HPE Aruba Networking AOS-10 AP and AOS-8 Instant software to one of the following versions (as applicable): - AOS-10 AP 10.8.x.x: 10.8.0.1 and above - AOS-10 AP 10.7.x.x: 10.7.2.3 and above - AOS-10 AP 10.4.x.x: 10.4.1.11 and above - AOS-8 Instant 8.13.x.x: 8.13.1.2 and above - AOS-8 Instant 8.12.x.x: 8.12.0.7 and above - AOS-8 Instant 8.10.x.x: 8.10.0.22 and above
- To minimize the likelihood of an attacker exploiting this vulnerability, HPE Aruba Networking recommends that management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above, along with accounting controls for tracking and logging user activities and resource usage.
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.