CVE-2026-23809: MAC Address Spoofing leads to Inter-BSSID Isolation Bypass Resulting in Traffic Redirection
A technique has been identified that adapts a known port-stealing method to Wi-Fi environments that use multiple BSSIDs. By leveraging the relationship between BSSIDs and their associated virtual ports, an attacker could potentially bypass inter-BSSID isolation controls. Successful exploitation may enable an attacker to redirect and intercept the victim's network traffic, potentially resulting in eavesdropping, session hijacking, or denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23809?
The severity of CVE-2026-23809 has been classified as high due to the potential for significant traffic redirection.
How do I fix CVE-2026-23809?
To fix CVE-2026-23809, upgrade to a non-vulnerable version of ArubaOS as specified in the security advisory.
Which ArubaOS versions are affected by CVE-2026-23809?
CVE-2026-23809 affects multiple versions of ArubaOS, specifically versions between 6.5.4.0 and 10.8.0.0.
What are the potential risks associated with CVE-2026-23809?
The risks associated with CVE-2026-23809 include unauthorized interception of network traffic and potential data breaches.
Is there a workaround for CVE-2026-23809?
There are no known workarounds for CVE-2026-23809; patching is the recommended solution.