CVE-2026-23596Disclosure(hpe / aruba_networking_private_5g_core)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch hpe aruba_networking_private_5g_core systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful exploitation could allow an attacker to disrupt services and negatively impact system availability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aruba_networking_private_5g_core

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-17); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
aruba_networking_private_5g_core

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-17: 1Mentions · 2026-02-18: 1Mentions · 2026-02-20: 1Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-20: 102-1702-1802-20
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-171
Disclosure1
2026-02-181
Disclosure1
2026-02-201
Patch1
Full discourse3 posts
  • iototsecnews@iototsecnews
    Patch

    Aruba の脆弱性 CVE-2026-23595 などが FIX:権限昇格や DoS 攻撃の恐れ https://iototsecnews.jp/2026/02/12/hpe-aruba-flaw-exposes-networking-devices-to-privilege-escalation-and-dos-attacks/ 企業や工場のプライベート 5G ネットワークを支える HPE Aruba Networking Private 5G Core に、管理者権限の奪取などを引き起こす複数の脆弱性が発見されました。最も深刻な脆弱性 CVE-2026-23595 は、アプリケーション API における認証プロセスの不備に起因します。通常、新しい管理者アカウントを作成するには厳格な本人確認が必要ですが、この脆弱性を悪用する外部の攻撃者は、正規の手続きを飛び越えて特権アカウントを作成できてしまう状態になっています。この他にも、サービスの強制再起動による業務停止 CVE-2026-23596 や、エラー画面からシステム構成が漏洩する問題 CVE-2026-23597 なども修正されました。ご利用のチームは、ご注意ください。 #Aruba #CVE20262317 #CVE20262318 #CVE20262319 #CVE20262320 #CVE20262321 #CVE20262322 #CVE20262323 #CVE202623595 #CVE202623596 #CVE202623597 #CVE202623598 #HPE #Private5GCorePlatform #Vulnerability

    Post summary

    The post reports that HPE Aruba Private 5G Core has multiple vulnerabilities, including CVE‑2026‑23595, that have been identified and fixed, detailing privilege‑escalation and DoS risks.

    01000129
    484 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23596 Unauthenticated Remote Service Restart Vulnerability in Management API https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23596

    Post summary

    A new CVE (2026-23596) describing an unauthenticated remote service restart vulnerability in a management API was disclosed via Vulmon. No PoC, exploit, patch or active exploitation details were provided.

    0001040
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23596 A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful exploitation coul… https://www.cve.org/CVERecord?id=CVE-2026-23596

    Post summary

    The CVE details a remote, unauthenticated attacker’s ability to trigger service restarts via the management API, but no PoC, exploit, active exploitation, patch, or false-positive information is provided.

    00010278
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphpearuba_networking_private_5g_core---

Explore more