Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-23820

CVE-2026-23820: 1 tracked advisory record across Aruba. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Aruba

1 advisory
  • Advisory severityHigh7.2

    High [CVE-2026-23820] AOS-10: vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environment

    CVE-2026-23820Source published Source updated

    A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environment. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. Affected products named by the advisory: Instant AP.

    Affected products in this advisory
    • AOS-10
    • Instant AP
    Source-reported affected versions
    • AOS-10 10.8.0.0
    • AOS-10 10.7.0.0 through 10.7.2.2
    • AOS-10 10.4.0.0 through 10.4.1.10
    • Instant AP 8.13.0.0 through 8.13.1.1

    2 more entries in the full advisory.

    Source-reported fixed versions
    • AOS-10 10.8.0.1 or above
    • AOS-10 10.7.2.3 or above
    • AOS-10 10.4.1.11 or above
    • Instant AP 8.13.1.2 or above

    2 more entries in the full advisory.

    Mitigation guidance
    • Upgrade affected HPE Aruba Networking devices to an applicable fixed release: AOS-10 10.8.0.1 or above, AOS-10 10.7.2.3 or above, AOS-10 10.4.1.11 or above, Instant AP 8.13.1.2 or above, Instant AP 8.12.0.7 or above, Instant AP 8.10.0.22 or above.
    • To address the vulnerabilities described above in the affected software branches, upgrade HPE Aruba Networking AOS-10 AP and AOS-8 Instant software to one of the following versions (as applicable): - AOS-10 AP 10.8.x.x: 10.8.0.1 and above - AOS-10 AP 10.7.x.x: 10.7.2.3 and above - AOS-10 AP 10.4.x.x: 10.4.1.11 and above - AOS-8 Instant 8.13.x.x: 8.13.1.2 and above - AOS-8 Instant 8.12.x.x: 8.12.0.7 and above - AOS-8 Instant 8.10.x.x: 8.10.0.22 and above
    Workarounds
    • To minimize the likelihood of an attacker exploiting this vulnerability, HPE Aruba Networking recommends that management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above, along with accounting controls for tracking and logging user activities and resource usage.

Android app · Google Play

Monitor future Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery