ThreatSynop[verified]@ThreatSynopPatch
HPE Aruba Private 5G Core has four disclosed CVEs, including an auth-bypass and DoS, with a patch available in version 1.25.1.0+; no PoC, exploit, or active exploitation is reported.
Autumn Good@autumn_good_35Disclosure
An authentication bypass vulnerability in the HPE Aruba Networking Private 5G Core API (CVE-2026-23595) allows an attacker to create an unauthorized administrative account. A vendor advisory with patch/workaround information is available.
iototsecnews@iototsecnewsPatch
HPE Aruba Private 5G Core devices have multiple critical flaws, notably CVE-2026-23595, which lets attackers gain privileged accounts by circumventing authentication. Vendor has issued fixes; users should apply patches immediately.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces CVE-2026-23595, an authentication bypass in an application API that allows the creation of unauthorized administrative accounts. No PoC, exploit code, active exploitation, or patch information is provided.
CVE@CVEnewDisclosure
CVE-2026-23595 is an authentication bypass vulnerability that lets attackers create unauthorized administrative accounts via the application API.
CVEFind.com@CveFindComDisclosure
CVE-2026-23595 is a high‑severity vulnerability that allows attackers to create unauthorized admin accounts via an API, potentially leading to privileged access, system changes, and data compromise. No PoC, exploit code, active exploitation, or patch information is provided.