CVE-2026-23818
8.8Hewlett Packard Enterprise · HPE Aruba Networking Private 5G Core On-Prem
An open redirect vulnerability in the HPE Aruba Networking Private 5G Core On-Prem GUI allows attackers to craft URLs that redirect authenticated users to malicious, credential-harvesting sites.
Executive summary
An open redirect vulnerability in HPE Aruba Networking Private 5G Core On-Prem poses a significant risk of credential theft through phishing attacks.
Vulnerability
This is an open redirect vulnerability located within the graphical user interface login flow. The flaw allows an unauthenticated attacker to manipulate a crafted URL to redirect victims to a spoofed login page designed to capture sensitive user credentials.
Business impact
Successful exploitation leads to the compromise of user credentials, which facilitates unauthorized access to the Private 5G Core infrastructure. Given the high CVSS score of 8.8, this flaw represents a significant risk to organizational integrity, potentially leading to full system compromise or lateral movement within the network.
Remediation
Immediate Action: Review the official Hewlett Packard Enterprise security advisory and apply the recommended firmware or software updates as soon as they are released for your environment.
Proactive Monitoring: Monitor authentication logs for suspicious redirect patterns or unusual traffic directed toward external domains originating from the management interface.
Compensating Controls: Implement strict URL filtering or Web Application Firewall rules to block requests containing suspicious redirect parameters until a permanent patch is deployed.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the elevated CVSS score and the existence of a proof-of-concept, this vulnerability should be prioritized for remediation. Administrators must identify all instances of the affected software and prepare to apply the vendor-provided patch immediately upon availability to prevent potential credential theft and unauthorized system access.