Ghostwire

CVE-2026-44873: A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their...

MEDIUM CVSS 5.5 EPSS 0.03%

Published: May 12, 2026 | Last Modified: May 12, 2026

Description

A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled. Existing sessions are not invalidated when credentials are revoked, enabling continued access until session expiration. An attacker with compromised credentials could exploit this behavior to maintain unauthorized access even after the account has been disabled.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.03% (10th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (2 articles)

References