CVE-2026-44874: Arubanetworks Arubaos

Medium severity, CVSS 4.9. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Successful exploitation of this vulnerability could result in the disclosure of confidential system information, potentially enabling further attacks against the affected device.

Affected products

  • Arubanetworks Arubaos: from 10.4.0.0, before 10.4.1.11 (fixed in 10.4.1.11); from 10.5.0.0, before 10.7.2.3 (fixed in 10.7.2.3); version 10.8.0.0 only

Published 2026-05-12. Last modified 2026-06-17.