A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attacker-controlled server hosting a spoofed login page prompting the unsuspecting victim to give away their credentials, which could then be captured by the attacker, before being redirected back to the legitimate login page.
References
| Link | Resource |
|---|---|
| https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05032en_us&docLocale=en_US | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-04-07 13:16
Updated : 2026-06-17 10:22
NVD link : CVE-2026-23818
Mitre link : CVE-2026-23818
CVE.ORG link : CVE-2026-23818
JSON object : View
Products Affected
hpe
- aruba_networking_private_5g_core
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
