CVE-2026-23821: Inconsistent input filtering allows Authenticated Command Injection in AOS-10 CLI
A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. Note: Access Points running AOS-8 Instant software are not affected by this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23821?
CVE-2026-23821 is classified as a high-severity vulnerability due to its potential for authenticated command injection.
How do I fix CVE-2026-23821?
To fix CVE-2026-23821, update the AOS-10 software to the latest version provided by Aruba that addresses this vulnerability.
Who is affected by CVE-2026-23821?
CVE-2026-23821 affects users of Access Points running AOS-10 that allow authenticated remote access.
What type of vulnerability is CVE-2026-23821?
CVE-2026-23821 is an authenticated command injection vulnerability that results from inconsistent input filtering in the AOS-10 CLI.
What are the risks associated with CVE-2026-23821?
Exploitation of CVE-2026-23821 could allow an authenticated attacker to execute arbitrary system commands, posing a risk to system integrity.