CVE-2026-23819
Hewlett Packard Enterprise (HPE) ArubaOS (AOS), arubaos
A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network. Successful exploitation could allow an attacker to compromise user data and potentially manipulate device configuration settings.
- CVSS
- 8.8
- EPSS
- 0.27% 19.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.13