CVE-2026-23595Disclosure(hpe / aruba_networking_private_5g_core)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch hpe aruba_networking_private_5g_core systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability to create privileged user accounts. Successful exploitation could allow an attacker to gain administrative access, modify system configurations, and access or manipulate sensitive data.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aruba_networking_private_5g_core

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-17); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
aruba_networking_private_5g_core

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-02-12: 1Mentions · 2026-02-13: 1Mentions · 2026-02-17: 2Mentions · 2026-02-18: 1Mentions · 2026-02-20: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-12: 1Technical Details · 2026-02-13: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-20: 102-1202-1302-1702-1802-20
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-121
Patch1
2026-02-131
Disclosure1
2026-02-172
Disclosure2
2026-02-181
Disclosure1
2026-02-201
Patch1
Full discourse6 posts
  • Autumn Good@autumn_good_35
    Disclosure

    『An authentication bypass in the application API allows an unauthorized administrative account to be created.』😨 CVE-2026-23595 HPESBNW05002 rev.1 - Multiple Vulnerabilities in HPE Aruba Networking Private 5G Core https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05002en_us&docLocale=en_US

    Post summary

    An authentication bypass vulnerability in the HPE Aruba Networking Private 5G Core API (CVE-2026-23595) allows an attacker to create an unauthorized administrative account. A vendor advisory with patch/workaround information is available.

    00011413
    6.7K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Aruba の脆弱性 CVE-2026-23595 などが FIX:権限昇格や DoS 攻撃の恐れ https://iototsecnews.jp/2026/02/12/hpe-aruba-flaw-exposes-networking-devices-to-privilege-escalation-and-dos-attacks/ 企業や工場のプライベート 5G ネットワークを支える HPE Aruba Networking Private 5G Core に、管理者権限の奪取などを引き起こす複数の脆弱性が発見されました。最も深刻な脆弱性 CVE-2026-23595 は、アプリケーション API における認証プロセスの不備に起因します。通常、新しい管理者アカウントを作成するには厳格な本人確認が必要ですが、この脆弱性を悪用する外部の攻撃者は、正規の手続きを飛び越えて特権アカウントを作成できてしまう状態になっています。この他にも、サービスの強制再起動による業務停止 CVE-2026-23596 や、エラー画面からシステム構成が漏洩する問題 CVE-2026-23597 なども修正されました。ご利用のチームは、ご注意ください。 #Aruba #CVE20262317 #CVE20262318 #CVE20262319 #CVE20262320 #CVE20262321 #CVE20262322 #CVE20262323 #CVE202623595 #CVE202623596 #CVE202623597 #CVE202623598 #HPE #Private5GCorePlatform #Vulnerability

    Post summary

    HPE Aruba Private 5G Core devices have multiple critical flaws, notably CVE-2026-23595, which lets attackers gain privileged accounts by circumventing authentication. Vendor has issued fixes; users should apply patches immediately.

    01000129
    484 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23595 Authentication Bypass in Application API Enabling Unauthorized Administrative Account Creation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23595

    Post summary

    The text announces CVE-2026-23595, an authentication bypass in an application API that allows the creation of unauthorized administrative accounts. No PoC, exploit code, active exploitation, or patch information is provided.

    0001033
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23595 An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability to cre… https://www.cve.org/CVERecord?id=CVE-2026-23595

    Post summary

    CVE-2026-23595 is an authentication bypass vulnerability that lets attackers create unauthorized administrative accounts via the application API.

    00010149
    56.4K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-23595: HIGH] Vulnerability in API enables unauthorized admin account creation. Exploitation may result in privileged access, system changes, and data compromise by remote attackers.#cve,CVE-2026-23595,#cybersecurity https://cvefind.com/CVE-2026-23595

    Post summary

    CVE-2026-23595 is a high‑severity vulnerability that allows attackers to create unauthorized admin accounts via an API, potentially leading to privileged access, system changes, and data compromise. No PoC, exploit code, active exploitation, or patch information is provided.

    0000047
    580 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 HPE Aruba Private 5G Core Hit by Pre-Auth API Flaws: Admin Takeover + DoS (4 CVEs) HPE disclosed four vulnerabilities in Aruba Networking Private 5G Core (1.24.3.0–1.24.3.3), including an auth-bypass in the application API (CVE-2026-23595, CVSS 8.8) that can let adjacent-network attackers create admin accounts, plus a management-API DoS and two info-disclosure bugs. This matters because Private 5G core control-plane compromise can enable full service disruption and sensitive configuration/user exposure—patching to 1.25.1.0+ is the only fix. 🎯 Target: Global / Enterprise Private 5G Networks #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/hpe-aruba-networking-vulnerability/

    Post summary

    HPE Aruba Private 5G Core has four disclosed CVEs, including an auth-bypass and DoS, with a patch available in version 1.25.1.0+; no PoC, exploit, or active exploitation is reported.

    0000042
    191 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphpearuba_networking_private_5g_core---

Explore more