CVE-2026-23823: Authenticated Command Injection leads to RCE in AOS-10 CLI Command
A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. NOTE: This vulnerability only impacts Access Points running AOS-10.7.x.x and above. AOS-10.4 AP and AOS-8 Instant software branches are not affected by this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23823?
CVE-2026-23823 is classified as a high-severity vulnerability due to the potential for remote command execution.
How do I fix CVE-2026-23823?
To mitigate CVE-2026-23823, update your Aruba AOS-10 software to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-23823?
CVE-2026-23823 affects Aruba AOS-10 systems, specifically versions 10.7.x.x and possibly earlier.
What type of attack does CVE-2026-23823 involve?
CVE-2026-23823 involves an authenticated command injection attack that could lead to remote code execution.
Can CVE-2026-23823 be exploited without authentication?
No, CVE-2026-23823 requires that the attacker is authenticated to exploit the command injection vulnerability.