logo

HPE Aruba Private 5G Platform Vulnerability Enables Credential Theft Attacks

ID: 04e47c1e-fb5a-574b-9469-bc5721fcd378

STIX ID: report--04e47c1e-fb5a-574b-9469-bc5721fcd378

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2026-04-10

Date Updated: 2026-04-21

Author: Abinaya

...
...

HPE disclosed CVE-2026-23818, an open redirect vulnerability in the Aruba Private 5G Core On-Prem GUI that allows attackers to craft malicious URLs which redirect authenticated users to attacker-controlled pages that mimic the legitimate login, capture credentials, and then return users to the real portal; the advisory warns of potential administrative account compromise and recommends applying patch HPESBNW05032, enabling MFA, and training users to detect suspicious links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.