High [CVE-2026-44869] AOS-10: Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems
This high-severity HPE Aruba Networking advisory covers CVE-2026-44869 affecting AOS-8 Mobility, AOS-10.
Android app · Google Play
Monitor future HPE Aruba Networking CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.
Affected products named by the advisory: AOS-8 Mobility.
- AOS-8 Mobility 8.13.0.0 through 8.13.1.1
- AOS-8 Mobility 8.12.0.0 through 8.12.0.6
- AOS-8 Mobility 8.10.0.0 through 8.10.0.21
- AOS-10 10.7.0.0 through 10.7.2.2
- AOS-10 10.8.0.0
- AOS-10 10.4.0.0 through 10.4.1.10
Official advisory · high-confidence parse· fetched 8 days ago·verify at source
- AOS-8 Mobility 8.13.1.2 or above
- AOS-8 Mobility 8.12.0.7 or above
- AOS-8 Mobility 8.10.0.22 or above
- AOS-10 10.8.0.1 or above
- AOS-10 10.7.2.3 or above
- AOS-10 10.4.1.11 or above
Official advisory · high-confidence parse· fetched 8 days ago·verify at source
Mitigation checklist
- Upgrade affected HPE Aruba Networking devices to an applicable fixed release: AOS-8 Mobility 8.13.1.2 or above, AOS-8 Mobility 8.12.0.7 or above, AOS-8 Mobility 8.10.0.22 or above, AOS-10 10.8.0.1 or above, AOS-10 10.7.2.3 or above, AOS-10 10.4.1.11 or above.
- Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.8.x.x: 10.8.0.1 and above; - AOS-10.7.x.x: 10.7.2.3 and above; - AOS-10.4.x.x: 10.4.1.11 and above; - AOS-8.13.x.x: 8.13.1.2 and above; - AOS-8.12.x.x: 8.12.0.7 and above; - AOS-8.10.x.x: 8.10.0.22 and above.
- To reduce the risk of exploitation, HPE Aruba Networking recommends restricting management interfaces to a dedicated Layer 2 segment or VLAN. In addition, Layer 3 firewall policies should be configured to limit access to UDP port 8444 exclusively to trusted infrastructure devices, such as managed access points (APs) and peer controllers.
Official advisory · high-confidence parse· fetched 8 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.