CVE-2026-44858: Authenticated Stack-Based Buffer Overflow in PAPI Services
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Successful exploitation could allow the attacker to execute arbitrary code with elevated privileges on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44858?
CVE-2026-44858 is classified as a medium severity vulnerability due to the potential for authenticated attackers to exploit it.
How do I fix CVE-2026-44858?
To fix CVE-2026-44858, upgrade to the latest version of AOS or apply the security patches provided by Aruba Networks.
What products are affected by CVE-2026-44858?
CVE-2026-44858 affects Aruba Networks AOS versions 8 and 10, as well as specific versions of their SD-WAN products.
Who can exploit CVE-2026-44858?
CVE-2026-44858 can be exploited by authenticated attackers with administrative privileges.
What type of vulnerability is CVE-2026-44858?
CVE-2026-44858 is a stack-based buffer overflow vulnerability in the management services of the AOS.