NOTE: This vulnerability only impacts Access Points running AOS-10.7.x.x and above. AOS-10.4 AP and AOS-8 Instant software branches are not affected by this vulnerability.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 13 May 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hpe
Hpe arubaos |
|
| Vendors & Products |
Hpe
Hpe arubaos |
Tue, 12 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
ssvc
|
Tue, 12 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. NOTE: This vulnerability only impacts Access Points running AOS-10.7.x.x and above. AOS-10.4 AP and AOS-8 Instant software branches are not affected by this vulnerability. | |
| Title | Authenticated Command Injection leads to RCE in AOS-10 CLI Command | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2026-05-13T03:58:36.867Z
Reserved: 2026-01-16T15:22:49.224Z
Link: CVE-2026-23823
Updated: 2026-05-12T19:23:35.872Z
Status : Awaiting Analysis
Published: 2026-05-12T19:16:29.053
Modified: 2026-05-13T15:35:17.550
Link: CVE-2026-23823
No data.
OpenCVE Enrichment
Updated: 2026-05-13T10:37:42Z