Security Advisory

CVE-2026-23818

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-04-07 12:18:11
Last updated 2026-04-07 13:17:32
Assigner hpe
State PUBLISHED

Description

A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attacker-controlled server hosting a spoofed login page prompting the unsuspecting victim to give away their credentials, which could then be captured by the attacker, before being redirected back to the legitimate login page.