CVE-2026-44860: Authenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating Systems
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44860?
CVE-2026-44860 is classified as a critical vulnerability due to its potential for remote code execution through authenticated SQL injection.
How do I fix CVE-2026-44860?
To mitigate CVE-2026-44860, upgrade to the latest patched version of AOS-8 or AOS-10 as recommended by the vendor.
What software is affected by CVE-2026-44860?
CVE-2026-44860 impacts AOS-8 and AOS-10 Operating Systems, including various versions of ArubaOS and SD-WAN.
What type of attack is associated with CVE-2026-44860?
CVE-2026-44860 is associated with authenticated remote code execution attacks via SQL injection.
Who can exploit CVE-2026-44860?
An authenticated attacker with administrative access can exploit CVE-2026-44860 to execute arbitrary code.