CVE-2026-23598: Unauthenticated Information Disclosure in application API allows sensitive system information exposure
Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such as user accounts, roles, and system configuration, as well as to gain insight into internal services and workflows, increasing the risk of unauthorized access and elevated privileges when combined with other vulnerabilities.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23598?
CVE-2026-23598 is classified as a high-severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2026-23598?
To fix CVE-2026-23598, ensure that your HPE Aruba Networking 5G Core server API is updated to the latest version that addresses this vulnerability.
What type of information can be disclosed by exploiting CVE-2026-23598?
Exploiting CVE-2026-23598 can allow an attacker to obtain sensitive system information through API error handling.
Who is affected by CVE-2026-23598?
CVE-2026-23598 affects users of the HPE Aruba Networking 5G Core server platform.
Is authentication required to exploit CVE-2026-23598?
No, CVE-2026-23598 can be exploited by unauthenticated remote attackers.