CVE-2026-23808
HIGH EPSS 17.8%
Published Mar 4, 20263mo ago · Modified Jun 17, 20261w ago
8.1 CVSS 3.1
Published Mar 4, 2026 3mo ago
Last Modified Jun 17, 2026 1w ago
Description
A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled Group Temporal Key (GTK) on a client device. Successful exploitation of this vulnerability could allow a remote malicious actor to perform unauthorized frame injection, bypass client isolation, interfere with cross-client traffic, and compromise network segmentation, integrity, and confidentiality.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Attack Vector Adjacent
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability None
Threat Intelligence
EPSS Exploit Probability
17.8% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-94 Improper Control of Generation of Code (Code Injection) Injection
Affected Products 23
| Vendor | Product | Version | Range |
|---|---|---|---|
| arubanetworks | arubaos | * | ≥6.5.4.0 – ≤8.10.0.21 |
| arubanetworks | arubaos | * | ≥8.11.0.0 – ≤8.12.0.6 |
| arubanetworks | arubaos | * | ≥8.13.0.0 – ≤8.13.1.1 |
| arubanetworks | arubaos | * | ≥10.3.0.0 – ≤10.4.1.10 |
| arubanetworks | arubaos | * | ≥10.5.0.0 – ≤10.7.2.2 |
| arubanetworks | arubaos | 10.8.0.0 | any |
| arubanetworks | 7010 | * | any |
| arubanetworks | 7030 | * | any |
| arubanetworks | 7205 | * | any |
| arubanetworks | 7210 | * | any |
| arubanetworks | 7220 | * | any |
| arubanetworks | 7240xm | * | any |
| arubanetworks | 7280 | * | any |
| arubanetworks | 9004 | * | any |
| arubanetworks | 9004-lte | * | any |
| arubanetworks | 9012 | * | any |
| arubanetworks | 9106 | * | any |
| arubanetworks | 9114 | * | any |
| arubanetworks | 9240 | * | any |
| arubanetworks | ap-634 | * | any |
| arubanetworks | ap-635 | * | any |
| arubanetworks | ap-654 | * | any |
| arubanetworks | ap-655 | * | any |
References 1
- support.hpe.com https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05026en_us&docLocale=en_US
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.