Heap-Based Buffer Overflow in AOS-8 and AOS-10 Network Management Service
CVE-2026-23827

7.5HIGH

Key Information:

Vendor

HP (HP)

Vendor
CVE Published:
12 May 2026

What is CVE-2026-23827?

A heap-based buffer overflow vulnerability has been identified in the network management service of AOS-8 and AOS-10. This flaw allows an unauthenticated remote attacker to potentially execute arbitrary code with privileged user rights on the affected operating system. The exploitation of this vulnerability could lead to severe consequences, including unauthorized access and control over the system, as well as a denial-of-service (DoS) condition affecting the system's processes. Users of these products are urged to review the security updates provided by Hewlett Packard Enterprise to mitigate potential risks.

Affected Version(s)

HPE Aruba Networking Wireless Operating System (AOS) 8.13.0.0 <= 8.13.1.1

HPE Aruba Networking Wireless Operating System (AOS) 8.13.0.0 <= 8.13.1.1

HPE Aruba Networking Wireless Operating System (AOS) 8.12.0.0 <= 8.12.0.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n3k
.