Insufficient Session Invalidation on User Account Deactivation in AOS-8 Operating System
Summary
| CVE | CVE-2026-44873 |
|---|---|
| State | PUBLISHED |
| Assigner | hpe |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-12 20:16:45 UTC |
| Updated | 2026-05-15 12:44:42 UTC |
| Description | A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled. Existing sessions are not invalidated when credentials are revoked, enabling continued access until session expiration. An attacker with compromised credentials could exploit this behavior to maintain unauthorized access even after the account has been disabled. |
Risk And Classification
Primary CVSS: v3.1 5.4 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS: 0.000350000 probability, percentile 0.105050000 (date 2026-05-20)
Problem Types: CWE-613 | CWE-613 CWE-613 Insufficient Session Expiration
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
| 3.1 | CNA | CVSS | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Arubanetworks | Arubaos | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Hewlett Packard Enterprise HPE | HPE Aruba Networking Wireless Operating System AOS | affected 8.13.0.0 8.13.1.1 semver | Not specified |
| CNA | Hewlett Packard Enterprise HPE | HPE Aruba Networking Wireless Operating System AOS | affected 8.12.0.0 8.12.0.6 semver | Not specified |
| CNA | Hewlett Packard Enterprise HPE | HPE Aruba Networking Wireless Operating System AOS | affected 8.10.0.0 8.10.0.21 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| support.hpe.com/hpesc/public/docDisplay | [email protected] | support.hpe.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: 0x50d (en)
There are currently no legacy QID mappings associated with this CVE.