PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23823 Hewlett Packard Enterprise (HPE) CVE debrief

CVE-2026-23823 is a command injection vulnerability in the command line interface of Access Points running AOS-10.7.x.x and above. This vulnerability allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability has a CVSS score of 7.2 and is classified as HIGH severity. Affected systems include Access Points running AOS-10.7.x.x and above, while AOS-10.4 AP and AOS-8 Instant software branches are not impacted. Network administrators and security teams should verify their systems, restrict CLI access, and monitor for suspicious activity.

Vendor
Hewlett Packard Enterprise (HPE)
Product
ArubaOS (AOS)
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-08-12
Advisory published
2026-05-12
Advisory updated
2026-08-12

Who should care

Network administrators and security teams managing Access Points with AOS-10.7.x.x and above should verify their systems, restrict CLI access, and monitor for suspicious activity. This includes reviewing current AOS-10 versions, limiting CLI access to necessary personnel, and conducting regular vulnerability scans. Additionally, applying vendor patches when available and tracking exceptions are crucial steps in managing this vulnerability effectively across affected platforms and environments within their operational scope and security responsibilities to ensure system integrity and protect against potential exploits that could lead to unauthorized command execution on affected devices under their management and oversight responsibilities for maintaining robust cybersecurity practices and compliance with organizational security policies and standards for vulnerability management and incident response preparedness in their respective domains of responsibility and control over affected systems and networks they manage or oversee within their organizational boundaries and jurisdictions of cybersecurity risk management and incident response operations and activities related to this CVE-2026-23823 vulnerability affecting Access Points running AOS-10.7.x.x and above versions of software installed on these devices that are connected to their networks or used within their operational environments and infrastructures they are responsible for securing and protecting against cyber threats and attacks and maintaining compliance with relevant laws regulations and standards related to information security and cybersecurity risk management practices and procedures for their organizations and stakeholders they serve and support through their cybersecurity operations and management activities and responsibilities for ensuring the confidentiality integrity and availability of information assets and resources under their care and control and oversight within their respective roles and responsibilities in their organizations and industries they operate in and serve and the communities they are part of and serve through their work and professional activities related to cybersecurity

Technical summary

CVE-2026-23823 is a command injection vulnerability in the command line interface of Access Points running AOS-10.7.x.x and above. An authenticated remote attacker could exploit this to execute arbitrary commands on the underlying operating system. The vulnerability has a CVSS score of 7.2 and HIGH severity. Only AOS-10.7.x.x and above are impacted; AOS-10.4 AP and AOS-8 Instant software branches are not affected. To mitigate, verify AOS-10 versions and restrict CLI access.

Defensive priority

Authenticated remote attackers could inject commands via the command line interface of affected Access Points running AOS-10.7.x.x and above. Verify AOS-10 versions and restrict CLI access.

Recommended defensive actions

  • Verify AOS-10 versions on Access Points
  • Restrict CLI access to necessary personnel
  • Monitor for suspicious CLI activity
  • Apply vendor patches when available
  • Conduct regular vulnerability scans

Evidence notes

The CVE-2026-23823 record indicates a command injection vulnerability in the CLI of Access Points running AOS-10.7.x.x and above. Official records show a CVSS score of 7.2 and HIGH severity. Only AOS-10.7.x.x and above are impacted; AOS-10.4 AP and AOS-8 Instant software branches are not affected.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-12T19:16:29.053Z and has not been modified since then.