CVE-2026-23822: Unauthenticated XML External Entity Injection in AOS-8 Instant allows Denial of Service
A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consumption upon user interaction, leading to service disruption or reduced availability of the affected system. NOTE: This vulnerability only impacts Access Points running AOS Instant 8.x.x.x
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23822?
CVE-2026-23822 is classified as a denial-of-service vulnerability.
How do I fix CVE-2026-23822?
To mitigate CVE-2026-23822, upgrade to a patched version of Aruba AOS Instant beyond 8.0.0.0.
Who is affected by CVE-2026-23822?
CVE-2026-23822 affects users of Aruba AOS Instant versions 8.0.0.0 to 8.x.x.x.
What type of attack can exploit CVE-2026-23822?
CVE-2026-23822 can be exploited through unauthenticated XML External Entity Injection.
What could result from the successful exploitation of CVE-2026-23822?
Successful exploitation of CVE-2026-23822 could lead to a denial-of-service condition on affected devices.