CVE-2026-44852

An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authenticated remote attacker to overwrite arbitrary files on the underlying operating system by exploiting improper input validation in the file path parameter. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system as a privileged user.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:*

History

15 May 2026, 21:16

Type Values Removed Values Added
CWE CWE-296

14 May 2026, 15:35

Type Values Removed Values Added
CPE cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
References () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05048en_us&docLocale=en_US - () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05048en_us&docLocale=en_US - Vendor Advisory
CWE NVD-CWE-noinfo
First Time Arubanetworks arubaos
Arubanetworks
Arubanetworks sd-wan

12 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-12 20:16

Updated : 2026-05-15 21:16


NVD link : CVE-2026-44852

Mitre link : CVE-2026-44852

CVE.ORG link : CVE-2026-44852


JSON object : View

Products Affected

arubanetworks

  • sd-wan
  • arubaos
CWE
NVD-CWE-noinfo CWE-296

Improper Following of a Certificate's Chain of Trust