CVE-2026-23819
published 2026-05-12CVE-2026-23819: A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to…
PriorityP352high8.8CVSS 3.1
AVAACLPRNUIRSCCHIHAH
EPSS
0.27%
17.4th percentile
A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network. Successful exploitation could allow an attacker to compromise user data and potentially manipulate device configuration settings.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arubanetworks | arubaos | — | — |
| arubanetworks | arubaos | >= 10.3.0.0 < 10.4.1.11 | 10.4.1.11 |
| arubanetworks | arubaos | >= 10.5.0.0 < 10.7.2.3 | 10.7.2.3 |
| arubanetworks | arubaos | 6.4.0.0 – 6.5.4.24 | — |
| arubanetworks | arubaos | >= 8.11.0.0 < 8.12.0.7 | 8.12.0.7 |
| arubanetworks | arubaos | >= 8.13.0.0 < 8.13.1.2 | 8.13.1.2 |
| arubanetworks | arubaos | >= 8.4.0.0 < 8.10.0.22 | 8.10.0.22 |
| hewlett_packard_enterprise | arubaos | — | — |
| hewlett_packard_enterprise | arubaos | 10.4.0.0 – 10.4.1.10 | — |
| hewlett_packard_enterprise | arubaos | 10.7.0.0 – 10.7.2.2 | — |
| hewlett_packard_enterprise | arubaos | 8.10.0.0 – 8.10.0.21 | — |
| hewlett_packard_enterprise | arubaos | 8.12.0.0 – 8.12.0.6 | — |
| hewlett_packard_enterprise | arubaos | 8.13.0.0 – 8.13.1.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
HPE ArubaOS up to 10.8.0.0 Remote Code Execution
vuldb·2026-05-12
CVE-2026-23819 [CRITICAL] HPE ArubaOS up to 10.8.0.0 Remote Code Execution
A vulnerability categorized as critical has been discovered in HPE ArubaOS up to 10.8.0.0. The affected element is an unknown function. The manipulation results in Remote Code Execution.
This vulnerability is identified as CVE-2026-23819. The attack can only be performed from the local network. There is not any exploit available.
GHSA
GHSA-7qhm-2x69-v62m: A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker
ghsa_unreviewed·2026-05-12
CVE-2026-23819 [HIGH] CWE-79 GHSA-7qhm-2x69-v62m: A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker
A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network. Successful exploitation could allow an attacker to compromise user data and potentially manipulate device configuration settings.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-12
Published