logo

HPE Aruba Patches High-Severity Credential Theft Flaw

ID: 841549bf-5dda-5695-a2c6-0b5a02d65242

STIX ID: report--841549bf-5dda-5695-a2c6-0b5a02d65242

Feed Name: securityonline.info

Threat Score
68/100

Date Published: 2026-04-10

Date Updated: 2026-04-23

Author: Ddos

...
...

HPE Aruba Networking disclosed a high-severity open-redirect vulnerability (CVE-2026-23818, CVSS 8.8) in its Private 5G Core On-Prem GUI that could redirect authenticated users to attacker-controlled spoofed login pages to capture credentials; affected versions are 1.25.3.0 and below, and HPE released a patch (1.25.3.1+) while recommending network isolation and enhanced monitoring as mitigations; no public exploit activity was reported at disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.