LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-44860

arubanetworks · arubaos

Published
CVSS7.2
Severityhigh
WeaknessCWE-89
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-44860

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-44860.