CVE-2026-23808: Client Isolation Bypass via GTK Manipulation
A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled Group Temporal Key (GTK) on a client device. Successful exploitation of this vulnerability could allow a remote malicious actor to perform unauthorized frame injection, bypass client isolation, interfere with cross-client traffic, and compromise network segmentation, integrity, and confidentiality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23808?
CVE-2026-23808 is categorized as a critical vulnerability due to the potential for exploitation resulting in unauthorized access to the Group Temporal Key.
How do I fix CVE-2026-23808?
To fix CVE-2026-23808, update affected ArubaOS versions to the latest security patches provided by Aruba Networks.
What systems are affected by CVE-2026-23808?
CVE-2026-23808 affects various versions of ArubaOS between 6.5.4.0 and 10.8.0.0.
What is the impact of CVE-2026-23808?
The impact of CVE-2026-23808 includes the risk of malicious actors installing an attacker-controlled Group Temporal Key, potentially leading to network compromise.
Is CVE-2026-23808 being actively exploited?
While there are no current reports of exploitation, it is advisable to address CVE-2026-23808 promptly to mitigate risks.