HPE Aruba AOS-8 Session Management Vulnerability Allowing Unauthorized Access After Account Deactivation

Vulnerability

A session management vulnerability exists in HPE Aruba Networking Operating System AOS-8. This vulnerability allows previously authenticated users to retain network access even after their accounts have been administratively disabled. When credentials are revoked, existing sessions are not invalidated, enabling continued access until the session expires. This behavior could be exploited by an attacker with compromised credentials to maintain unauthorized access despite account deactivation.

Impact

Exploitation of this vulnerability could lead to unauthorized access to network resources, allowing an attacker to interact with the network as if they were a legitimate user, even after their account has been disabled.

Remediation

To address this vulnerability, users should delete the affected account using the 'aaa user delete' command. For more information, consult the HPE Aruba Networking Support Portal.

Added: May 12, 2026, 8:31 PM
Updated: May 12, 2026, 8:31 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
0.6
exploitability
5.9
remediation
8.3
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.