A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthenticated remote attacker to achieve remote code execution. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code as a privileged user on the underlying operating system, potentially leading to a system compromise. Exploitation may also result in a denial-of-service (DoS) condition affecting the impacted system process.
References
| Link | Resource |
|---|---|
| https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05048en_us&docLocale=en_US | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
15 May 2026, 12:45
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Arubanetworks arubaos
Arubanetworks Arubanetworks sd-wan |
|
| References | () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05048en_us&docLocale=en_US - Vendor Advisory | |
| CPE | cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:* cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* |
13 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-122 |
12 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-12 20:16
Updated : 2026-05-15 12:45
NVD link : CVE-2026-23827
Mitre link : CVE-2026-23827
CVE.ORG link : CVE-2026-23827
JSON object : View
Products Affected
arubanetworks
- sd-wan
- arubaos
CWE
CWE-122
Heap-based Buffer Overflow
