HPE Aruba has released a security update to fix a vulnerability affecting HPE Aruba Networking Private 5G Core.
The addressed vulnerability could allow the attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to the attacker-controlled server hosting a spoofed login page, prompting the unsuspecting victim to give away their credentials, which could then be captured by the attacker before being redirected back to the legitimate login page.
The addressed vulnerability:
HPE Aruba Networking Private 5G Core Open Redirect Vulnerability (CVE-2026- 23818):
CVE-2026-23818
The enterprise should deploy this patch as soon as the testing phase is completed.
| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |