SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system.
Metrics
Affected Vendors & Products
References
History
Thu, 14 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arubanetworks
Arubanetworks arubaos Arubanetworks sd-wan |
|
| CPEs | cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:* cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Arubanetworks
Arubanetworks arubaos Arubanetworks sd-wan |
Wed, 13 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 May 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hpe
Hpe arubaos |
|
| Vendors & Products |
Hpe
Hpe arubaos |
Tue, 12 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 |
Tue, 12 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system. | |
| Title | Authenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating Systems | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hpe
Published: 2026-05-12T19:06:35.878Z
Updated: 2026-05-13T17:58:29.693Z
Reserved: 2026-05-07T21:29:07.696Z
Link: CVE-2026-44861
Updated: 2026-05-13T17:58:14.259Z
Status : Analyzed
Published: 2026-05-12T20:16:44.720
Modified: 2026-05-14T18:41:11.913
Link: CVE-2026-44861
No data.