Remote File Access Vulnerability in HPE AOS-10 Gateway Management Interface
CVE-2026-44874

4.9MEDIUM

Key Information:

Vendor

HP (HP)

Vendor
CVE Published:
12 May 2026

What is CVE-2026-44874?

A security flaw in the web-based management interface of the HPE AOS-10 Gateway allows authenticated remote attackers to access sensitive files on the underlying operating system. Exploitation of this vulnerability could lead to unauthorized disclosure of confidential system information, which may facilitate further cyber attacks against the compromised device.

Affected Version(s)

HPE Aruba Networking Wireless Operating System (AOS) 10.7.0.0 <= 10.7.2.2

HPE Aruba Networking Wireless Operating System (AOS) 10.7.0.0 <= 10.7.2.2

HPE Aruba Networking Wireless Operating System (AOS) 10.8.0.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zzcentury
.