CVE-2026-23822
CVE-2026-23822: 1 tracked advisory record across Aruba. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Aruba
1 advisory- Advisory severityMedium5.3
Medium [CVE-2026-23822] AOS-8: vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition
CVE-2026-23822Source published Source updated
A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consumption upon user interaction, leading to service disruption or reduced availability of the affected system. NOTE: This vulnerability only impacts Access Points running AOS Instant 8.x.x.x Affected product named by the advisory: Instant AP.
- Affected products in this advisory
- Instant AP
- Source-reported affected versions
- Instant AP 8.13.0.0 through 8.13.1.1
- Instant AP 8.12.0.0 through 8.12.0.6
- Instant AP 8.10.0.0 through 8.10.0.21
- Source-reported fixed versions
- Instant AP 8.13.1.2 or above
- Instant AP 8.12.0.7 or above
- Instant AP 8.10.0.22 or above
- Mitigation guidance
- Upgrade affected HPE Aruba Networking devices to an applicable fixed release: Instant AP 8.13.1.2 or above, Instant AP 8.12.0.7 or above, Instant AP 8.10.0.22 or above.
- To address this vulnerability, upgrade HPE Aruba Networking AOS-8 Instant software to one of the following versions (as applicable): - AOS-8 Instant 8.13.x.x: 8.13.1.2 and above - AOS-8 Instant 8.12.x.x: 8.12.0.7 and above - AOS-8 Instant 8.10.x.x: 8.10.0.22 and above
- Workarounds
- To minimize the likelihood of an attacker exploiting this vulnerability, HPE Aruba Networking recommends that management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above, along with accounting controls for tracking and logging user activities and resource usage.
Android app · Google Play
Monitor future Aruba CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.