CVE-2026-44873: Insufficient Session Invalidation on User Account Deactivation in AOS-8 Operating System
A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled. Existing sessions are not invalidated when credentials are revoked, enabling continued access until session expiration. An attacker with compromised credentials could exploit this behavior to maintain unauthorized access even after the account has been disabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44873?
CVE-2026-44873 is a high-severity vulnerability due to inadequate session invalidation after user account deactivation.
How do I fix CVE-2026-44873?
To fix CVE-2026-44873, ensure that your system is updated to the latest version of AOS-8 that addresses this session management flaw.
What impact does CVE-2026-44873 have on users?
CVE-2026-44873 allows previously authenticated users to maintain network access even after their accounts are disabled, posing a security risk.
Is CVE-2026-44873 present in earlier versions of ArubaOS?
CVE-2026-44873 specifically affects ArubaOS 8, and prior versions may not have this vulnerability.
Who is affected by CVE-2026-44873?
Organizations using ArubaOS 8 with user account deactivation features may be affected by CVE-2026-44873.