Skip to content
VulniPulse
High8.8HPE Aruba Networking

High [CVE-2026-23818] vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL

This high-severity HPE Aruba Networking advisory covers CVE-2026-23818 affecting Private 5G Core.

CVE-2026-23818 Published Apr 7, 2026Updated by vendor Jun 17, 2026
Affected products & platforms
HPE Aruba NetworkingUnclassified
Open vendor advisory

Android app · Google Play

Monitor future HPE Aruba Networking CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL.

Successful exploitation may redirect an authenticated user to an attacker-controlled server hosting a spoofed login page prompting the unsuspecting victim to give away their credentials, which could then be captured by the attacker, before being redirected back to the legitimate login page.

Affected versions
  • Private 5G Core 1.0.0.0 through 1.25.3.0

Official advisory · high-confidence parse· fetched 1 month ago·verify at source

Fixed versions
  • Private 5G Core 1.25.3.1 or above

Official advisory · high-confidence parse· fetched 1 month ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Upgrade affected HPE Aruba Networking devices to an applicable fixed release: Private 5G Core 1.25.3.1 or above.
  • To resolve the vulnerabilities described above, it is recommended to upgrade the software to the following version: - HPE Aruba Networking Private 5G Core 1.25.3.1 and above The latest version of the product is available for download at <https://myenterpriselicense.hpe.com/> HPE Aruba Networking does not evaluate or patch HPE Aruba Networking Private 5G Core Software versions that have reached their End of Support (EoS) milestone. For more information about HPE Aruba Networking Product Lifecycle and versioning policy, please visit: <https://www.hpe.com/psnow/doc/4aa5-5978enw?jumpid=in_pdfviewer-psnow>
Temporary workarounds
  • To minimize the likelihood of an attacker exploiting this vulnerability, HPE Aruba Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above, along with accounting controls for tracking and logging user activities and resource usage.

Official advisory · high-confidence parse· fetched 1 month ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.