CVE-2026-23820: Inconsistent input filtering allows Authenticated Command Injection in AOS-8 Instant and AOS-10 CLI
A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environment. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23820?
CVE-2026-23820 has been classified as a critical vulnerability due to its potential to allow authenticated command injection in affected systems.
How do I fix CVE-2026-23820?
To fix CVE-2026-23820, ensure that your AOS-8 Instant or AOS-10 systems are updated to the latest firmware version provided by Aruba Networks.
What are the affected products for CVE-2026-23820?
CVE-2026-23820 affects Aruba Networks AOS-8 Instant and AOS-10 products.
Who can exploit CVE-2026-23820?
CVE-2026-23820 can be exploited by authenticated remote attackers who gain access to the command line interface.
What potential impact does CVE-2026-23820 have on affected systems?
CVE-2026-23820 can lead to unauthorized execution of system commands, compromising the integrity and security of affected devices.