Session Management Vulnerability in AOS-8 by HPE
CVE-2026-44873
5.4MEDIUM
What is CVE-2026-44873?
AOS-8 is affected by a session management vulnerability that permits users to retain access to the network even after their accounts are administratively disabled. This occurs because existing sessions do not get invalidated upon credential revocation, allowing unauthorized users to exploit this oversight and maintain access until their session expires. Organizations using AOS-8 must address this issue to protect sensitive data and prevent potential breaches.
Affected Version(s)
HPE Aruba Networking Wireless Operating System (AOS) 8.13.0.0 <= 8.13.1.1
HPE Aruba Networking Wireless Operating System (AOS) 8.13.0.0 <= 8.13.1.1
HPE Aruba Networking Wireless Operating System (AOS) 8.12.0.0 <= 8.12.0.6
