PT-2026-40339 · Aruba · Instant Aos

Nicholas Starke

·

Published

2026-05-12

·

Updated

2026-05-12

·

CVE-2026-23822

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions AOS Instant versions 8.x.x.x
Description A flaw in the XML handling component of AOS-8 DHCP services allows an unauthenticated remote attacker to trigger a denial-of-service condition. This occurs through excessive resource consumption upon user interaction, which can lead to service disruption or reduced system availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

XML Entity Expansion

Weakness Enumeration

Related Identifiers

CVE-2026-23822

Affected Products

Instant Aos