CVE-2026-44862: Authenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating Systems
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44862?
CVE-2026-44862 is considered a critical vulnerability due to its potential for authenticated remote code execution through SQL injection.
How do I fix CVE-2026-44862?
To mitigate CVE-2026-44862, update your AOS-8 or AOS-10 to the latest patched version provided by Aruba Networks.
Which systems are affected by CVE-2026-44862?
CVE-2026-44862 affects AOS-8 and AOS-10 operating systems along with their various versions within specified ranges.
What causes CVE-2026-44862?
CVE-2026-44862 is caused by SQL injection vulnerabilities in several service components exposed through the AOS command-line interface and management protocol.
Who is at risk from CVE-2026-44862?
Authenticated users with administrative access to affected AOS systems are at risk from CVE-2026-44862 if proper security measures are not implemented.