A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attacker-controlled server hosting a spoofed login page prompting the unsuspecting victim to give away their credentials, which could then be captured by the attacker, before being redirected back to the legitimate login page.
References
| Link | Resource |
|---|---|
| https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05032en_us&docLocale=en_US | Vendor Advisory |
Configurations
History
14 Apr 2026, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05032en_us&docLocale=en_US - Vendor Advisory | |
| First Time |
Hpe aruba Networking Private 5g Core
Hpe |
|
| CPE | cpe:2.3:a:hpe:aruba_networking_private_5g_core:*:*:*:*:*:*:*:* |
07 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-601 |
07 Apr 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-07 13:16
Updated : 2026-04-14 21:15
NVD link : CVE-2026-23818
Mitre link : CVE-2026-23818
CVE.ORG link : CVE-2026-23818
JSON object : View
Products Affected
hpe
- aruba_networking_private_5g_core
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
