PT-2026-40362 · Aruba · Aos-8+1

Zzcentury

·

Published

2026-05-12

·

Updated

2026-05-15

·

CVE-2026-44852

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AOS-8 (affected versions not specified) AOS-10 (affected versions not specified)
Description An authenticated remote code execution issue exists in the web-based management interface. Improper input validation in the file path parameter within the certificate download functionality allows an authenticated remote attacker to overwrite arbitrary files on the underlying operating system. This can lead to the execution of arbitrary commands as a privileged user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44852

Affected Products

Aos 10
Aos-8