{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale",
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "notes": [
      {
        "category": "summary",
        "text": "Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an unauthenticated attacker to bypass route-level authentication and authorization. When a public router matches on a PathPrefix rule and applies the StripPrefix middleware, a request path containing .. or its percent-encoded form %2e%2e can match the public route at routing time and then, after the prefix is stripped and the path is normalized, resolve to a path served by a separate, authenticated router. As a result, an attacker can reach protected backend paths - such as admin or internal configuration endpoints - without satisfying the authentication middleware attached to the protected router. This vulnerability is fixed in 2.11.48, 3.6.19, and 3.7.3.",
        "title": "Summary"
      },
      {
        "category": "general",
        "text": "HPE Aruba Networking Private 5G Core versions prior to 1.26.1.1",
        "title": "Affected Products"
      },
      {
        "category": "general",
        "text": "HPE Aruba Networking products not listed under affected products are not impacted by this vulnerability.",
        "title": "Unaffected Products"
      },
      {
        "category": "other",
        "text": "HPE Aruba Networking is aware of public discussion and proof-of-concept code regarding this vulnerability. There are no known reports of active exploitation against HPE Aruba Networking customers at the time of this advisory.",
        "title": "Exploitation and Public Discussion"
      },
      {
        "category": "general",
        "text": "Complete information on reporting security vulnerabilities in HPE Aruba Networking products and obtaining assistance with security incidents is available at:\nhttp://www.hpe.com/support/security-response-policy\n\nFor reporting NEW HPE Aruba Networking security issues, email can be sent to aruba-sirt@hpe.com. For sensitive information we encourage the use of PGP encryption. Our public keys can be found at: https://www.hpe.com/info/psrt-pgp-key ",
        "title": "HPE Aruba Networking SIRT Security Procedures"
      },
      {
        "category": "legal_disclaimer",
        "text": "(c) Copyright 2026 by Hewlett Packard Enterprise Development LP. This advisory may be redistributed freely after the release date of the advisory, provided that the redistributed copies are complete and unmodified, including all data and version information.",
        "title": "Legal Disclaimer"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "Email: hpe-networking-sirt@hpe.com - For further details please see https://www.hpe.com/support/security-response-policy",
      "issuing_authority": "HPE Aruba Networking's Security Incident Response Team (SIRT) is responsible for receiving, tracking, managing, and disclosing vulnerabilities in HPE Aruba Networking products. The HPE Aruba Networking SIRT actively works with industry, non-profit, government organizations, and the security community when vulnerabilities are reported.",
      "name": "HPE Networking",
      "namespace": "https://www.hpe.com/support/security-response-policy"
    },
    "references": [
      {
        "summary": "Original Advisory",
        "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05083en_us&docLocale=en_US"
      },
      {
        "summary": "HPE Aruba Networking Security Advisory Archive",
        "url": "https://support.hpe.com/connect/s/securitybulletinlibrary/"
      },
      {
        "summary": "HPE Aruba Networking Product Security Incident Response Policy",
        "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00100637en_us"
      }
    ],
    "title": "Private 5G Core, Traefik StripPrefix Route-Level Auth  Bypass via Path Normalization (CVE-2026-48020)",
    "tracking": {
      "current_release_date": "2026-07-21T17:00:00.000Z",
      "generator": {
        "date": "2026-07-21T14:08:05.734Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.6"
        }
      },
      "id": "HPESBNW05083",
      "initial_release_date": "2026-07-21T17:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-07-21T17:00:00.000Z",
          "number": "1",
          "summary": "Initial Release"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "1.26.1.2",
                "product": {
                  "name": "Private 5G Core",
                  "product_id": "1.26.1.2"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=1.26.0.0|<=1.26.1.1",
                "product": {
                  "name": "Private 5G Core",
                  "product_id": ">=1.26.0.0|<=1.26.1.1"
                }
              }
            ],
            "category": "product_name",
            "name": "Private 5G Core"
          }
        ],
        "category": "vendor",
        "name": "HPE Aruba Networking"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "H4ck2"
          ]
        }
      ],
      "cve": "CVE-2026-48020",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in Traefik could allow an attacker to bypass configured authentication or authorization controls when specific routing configurations are in use. Successful exploitation could permit unauthorized access to protected \nbackend resources.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-588",
          "title": "Internal Reference"
        }
      ],
      "product_status": {
        "fixed": [
          "1.26.1.2"
        ],
        "known_affected": [
          ">=1.26.0.0|<=1.26.1.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-21T17:00:00.000Z",
          "details": "HPE Aruba Networking recommends upgrading Private 5G Core to versions 1.26.1.2 or later. The software updates can be found on My HPE Software Center:\n\n  - Software and documentation for Customers (available with an order/support contract): https://myenterpriselicense.hpe.com/cwp-ui/software",
          "product_ids": [
            "1.26.1.2"
          ],
          "url": "https://myenterpriselicense.hpe.com/cwp-ui/software"
        },
        {
          "category": "workaround",
          "date": "2026-07-21T17:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these \nvulnerabilities, HPE Aruba Networking recommends that \nmanagement interfaces be restricted to a dedicated layer 2 \nsegment/VLAN and/or controlled by firewall policies at \nlayer 3 and above, along with accounting controls for \ntracking and logging user activities and resource usage. \nYou may contact HPE Services - HPE Aruba Networking for \nassistance if needed. For more information, please visit \nHPE Networking Support Portal at \nhttps://networkingsupport.hpe.com/home",
          "product_ids": [
            ">=1.26.0.0|<=1.26.1.1"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.1,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.1,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            ">=1.26.0.0|<=1.26.1.1"
          ]
        }
      ],
      "title": "Traefik StripPrefix Route-Level Auth Bypass via Path  Normalization (CVE-2026-48020)"
    }
  ]
}