CVE-2026-23827: Unauthenticated Remote Code Execution via Heap Buffer Overflow in Network Management Service
A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthenticated remote attacker to achieve remote code execution. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code as a privileged user on the underlying operating system, potentially leading to a system compromise. Exploitation may also result in a denial-of-service (DoS) condition affecting the impacted system process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23827?
The severity of CVE-2026-23827 is rated high with a score of 7.5.
What does CVE-2026-23827 affect?
CVE-2026-23827 affects the Network Management Service in AOS-8 and AOS-10 platforms.
How do I fix CVE-2026-23827?
To fix CVE-2026-23827, update to the latest version of ArubaOS that addresses this vulnerability.
What type of attack does CVE-2026-23827 allow?
CVE-2026-23827 allows unauthenticated remote code execution through a heap buffer overflow.
Who is at risk from CVE-2026-23827?
Unauthenticated remote attackers are at risk from CVE-2026-23827, as it allows them to execute arbitrary code.