-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 HPE Aruba Networking Product Security Advisory ============================================== Advisory ID: HPESBNW05032 CVE: CVE-2026-23818 Publication Date: 2026-APR-07 Status: Confirmed Severity: High Revision: 1 Title ===== Open Redirect Vulnerability in HPE Aruba Networking Private 5G Core On-Prem Overview ======== HPE Aruba Networking has released a software update for the HPE Aruba Networking Private 5G Core On-Prem Platform that addresses an open redirect vulnerability. Affected Products ================= This vulnerability affects HPE Aruba Networking Private 5G Core On-Prem in the following software versions unless specifically noted otherwise in the details section: HPE Aruba Networking Private 5G Core: - 1.25.3.0 and below Unaffected Products ================= Any other HPE Aruba Networking products not specifically listed above are not affected by this vulnerability. Details ======= Open Redirect Vulnerability in HPE Aruba Networking Private 5G Core On-Prem (CVE-2026-23818) - - -------------------------------------------------------------- A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attacker-controlled server hosting a spoofed login page prompting the unsuspecting victim to give away their credentials, which could then be captured by the attacker, before being redirected back to the legitimate login page. Internal Reference(s): VULN-257 Severity: High CVSS v3.1 Base Score: 8.8 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Discovery: This vulnerability was internally discovered and reported by HPE Aruba Networking Private 5G Core Engineering. Resolution ========== To resolve the vulnerability described above, it is recommended to upgrade the software to the following version: - HPE Aruba Networking Private 5G Core 1.25.3.1 and above The latest version of the product is available for download at https://myenterpriselicense.hpe.com/. HPE Aruba Networking does not evaluate or patch HPE Aruba Networking Private 5G Core Software versions that have reached their End of Support (EoS) milestone. For more information about HPE Aruba Networking Product Lifecycle and versioning policy, please visit: https://www.hpe.com/psnow/doc/4aa5-5978enw?jumpid=in_pdfviewer-psnow Workaround ========== To minimize the likelihood of an attacker exploiting this vulnerability, HPE Aruba Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above, along with accounting controls for tracking and logging user activities and resource usage. Exploitation and Public Discussion ================================== HPE Aruba Networking is not aware of any public discussion or exploit code targeting this specific vulnerability as of the release date of the advisory. Revision History ================ Revision 1 / 2026-APR-07 / Initial release HPE Aruba Networking SIRT Security Procedures ============================== Complete information on reporting security vulnerabilities in HPE Aruba Networking products and obtaining assistance with security incidents is available at: https://www.hpe.com/support/security-response-policy For reporting *NEW* HPE Aruba Networking security issues, email can be sent to aruba-sirt(at)hpe.com. For sensitive information we encourage the use of PGP encryption. Our public keys can be found at: https://www.hpe.com/info/psrt-pgp-key (c) Copyright 2026 by Hewlett Packard Enterprise Development LP. This advisory may be redistributed freely after the release date given at the top of the text, provided that the redistributed copies are complete and unmodified, including all data and version information. -----BEGIN PGP SIGNATURE----- iQHLBAEBCAA1FiEEQT1cq06WWXH+NEKru7x8adyj7A4FAmnNTakXHHNlY3VyaXR5 LWFsZXJ0QGhwZS5jb20ACgkQu7x8adyj7A7JawwAjvmFj+ASF/05GAw3aLriKqTC TNBrQYNkL1soREoGnuZA478sCGOG3MC7U8yNpoHrsOISg+XA69iK5Sy5pBXQ+xFn BbBSaQJg24iwaBCZKe+107yPcCv5eoCWLGdrbB0v7EoQjC/EdIXhoNAI0Y1Tky1g qCmYC/NB9+Q6b6Gms5F39MT1uar7qzpJ6hE75TNK24bk5csKI4yEAXRAET7pVLTC dlPe6sIuv3XdJTgEuYeDR/fEk6I5plCExcOe8KR0Uto9DXRTzJyixiwfEZfE5Zhs h93lzEjn3/ryqJYxb8qd6mKh7cDaI3reItJNxMXPedjlMO58Brr16VDtvzg9wGHj BxlU3lecoDuI6EMzqgeFjWK4/8ZFam7b23tJQ2yrfn1ZYVZL3kgn/KKkJt1ySgV/ ooobu28k1WPj7WbvNlxOw+nUHD018O5e5nQJ/pbQDOjFTjJ4yMPeBSmCkgyYxrcf rGt+/FEN7LburLQX4shLGWhztEq6+euz57lPvjBL =Si5w -----END PGP SIGNATURE-----