CVE-2026-23818Disclosure(hpe / aruba_networking_private_5g_core)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attacker-controlled server hosting a spoofed login page prompting the unsuspecting victim to give away their credentials, which could then be captured by the attacker, before being redirected back to the legitimate login page.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aruba_networking_private_5g_core

Threat summary

  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 2 mentions (2026-04-07); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
aruba_networking_private_5g_core

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-07: 2Mentions · 2026-04-14: 1Mentions · 2026-04-17: 1Mentions · 2026-04-19: 1Technical Details · 2026-04-07: 2Technical Details · 2026-04-17: 104-0704-1404-1704-19
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-072
Disclosure2
2026-04-141
Disclosure1
2026-04-171
Disclosure1
2026-04-191
Disclosure1
Full discourse5 posts
  • CyberTech Insights@CyberTech_In
    Disclosure

    A flaw in HPE Aruba Networking Private 5G Core enables credential theft via login redirects. CVE-2026-23818 uses phishing-style attacks to capture admin credentials without malware. 𝐑𝐞𝐚𝐝 𝐟𝐮𝐥𝐥 𝐬𝐭𝐨𝐫𝐲 : https://cybertechnologyinsights.com/cybersecurity/hpe-aruba-5g-flaw-enables-credential-theft-attacks/ #CyberSecurity #5G #Infosec https://t.co/WIei7g63dX

    Post summary

    The tweet announces a newly disclosed flaw (CVE-2026-23818) that could allow credential theft through login redirects, but it lacks concrete PoC, exploit, patch, or technical depth.

    01010328
    17 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    HPE Aruba Private 5G Core に脆弱性 CVE-2026-23818 が FIX:オープン・リダイレクトと認証情報の窃取 https://iototsecnews.jp/2026/04/10/hpe-aruba-private-5g-vulnerability-opens-door-to-credential-theft-attacks/ 今回ご紹介した CVE-2026-23818 は、ログイン時のリダイレクト処理において、遷移先の URL を正しく検証できていないことが根本的な原因となっています。システムが外部からの入力をそのまま信じてしまい、サニタイズ (無害化) を怠ると、攻撃者が用意した偽のサイトへ利用者を誘導できてしまうのです。一見すると正規の画面と見分けがつかないため、認証情報を入力する際はブラウザの URL バーを確認する習慣が大切です。ご利用のチームは、ご注意ください。 #ArubaPrivate5GCore #CVE202623818 #HPE #Vulnerability

    Post summary

    The article discloses CVE‑2026‑23818 as an unvalidated redirect vulnerability in HPE Aruba Private 5G Core that can lead to credential theft, but it does not mention a PoC, exploit code, or patch.

    01000344
    484 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23818 A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an ope… https://www.cve.org/CVERecord?id=CVE-2026-23818

    Post summary

    The tweet briefly announces CVE‑2026‑23818 as a GUI‑related vulnerability in HPE Aruba Private 5G Core On‑Prem that could be abused by attackers, but it lacks PoC details, exploit tools, active exploitation evidence, patches, or in‑depth technical information.

    00000581
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23818 Open Redirect Vulnerability in HPE Aruba Networking Private 5G Core On-Prem GUI https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23818

    Post summary

    CVE-2026-23818 is an open redirect vulnerability in HPE Aruba Networking Private 5G Core On-Prem GUI; the text merely announces the flaw without providing PoC, exploit, patch, or evidence of active exploitation.

    00000214
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-23818: HIGH] Vulnerability found in HPE Aruba Networking Private 5G Core On-Prem GUI login flow could lead to credential theft via open redirect using a crafted URL.#cve,CVE-2026-23818,#cybersecurity https://cvefind.com/CVE-2026-23818

    Post summary

    A high‑severity vulnerability (CVE-2026-23818) in the HPE Aruba Networking Private 5G Core On‑Prem GUI login flow is disclosed, enabling credential theft through an open redirect, with no PoC, exploit code, or patch information provided.

    00000203
    619 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphpearuba_networking_private_5g_core---

Explore more