Skip to content
VulniPulse
Advisory severityHigh7.2HPE Aruba Networking

High [CVE-2026-23823] AOS-10: vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection

This high-severity HPE Aruba Networking advisory covers CVE-2026-23823 affecting AOS-10.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-23823 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
HPE Aruba NetworkingAOS-10Wireless & ControllersInstantArubaOS
Open source advisory

Android app · Google Play

Monitor future HPE Aruba Networking CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

NOTE: This vulnerability only impacts Access Points running AOS-10.7.x.x and above. AOS-10.4 AP and AOS-8 Instant software branches are not affected by this vulnerability.

Affected versions
  • AOS-10 10.8.0.0
  • AOS-10 10.7.0.0 through 10.7.2.2

Official advisory · high-confidence parse· fetched 26 days ago·verify at source

Fixed versions
  • AOS-10 10.8.0.1 or above
  • AOS-10 10.7.2.3 or above

Official advisory · high-confidence parse· fetched 26 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Upgrade affected HPE Aruba Networking devices to an applicable fixed release: AOS-10 10.8.0.1 or above, AOS-10 10.7.2.3 or above.
  • To address this vulnerability, upgrade HPE Aruba Networking AOS-10 AP software to one of the following versions (as applicable): - AOS-10 AP 10.8.x.x: 10.8.0.1 and above - AOS-10 AP 10.7.x.x: 10.7.2.3 and above
Temporary workarounds
  • To minimize the likelihood of an attacker exploiting this vulnerability, HPE Aruba Networking recommends that management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above, along with accounting controls for tracking and logging user activities and resource usage.

Official advisory · high-confidence parse· fetched 26 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.