CVE-2026-23818
HIGHOpen Redirect Vulnerability in HPE Aruba Networking Private 5G Core On-Prem
Title source: cnaDescription
A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attacker-controlled server hosting a spoofed login page prompting the unsuspecting victim to give away their credentials, which could then be captured by the attacker, before being redirected back to the legitimate login page.
Scores
CVSS v3
8.8
EPSS
0.0004
EPSS Percentile
13.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-601
Status
published
Products (2)
Hewlett Packard Enterprise (HPE)/Private 5G Core
1.0.0.0 - 1.25.3.0
hpe/aruba_networking_private_5g_core
< 1.25.3.1
Published
Apr 07, 2026
Tracked Since
Apr 07, 2026