CVE-2026-23817: Unauthenticated Open Redirect allows URL Manipulation in Web Interface
A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23817?
CVE-2026-23817 is considered a high severity vulnerability due to its potential for unauthenticated exploitation.
How do I fix CVE-2026-23817?
To mitigate CVE-2026-23817, it is recommended to update the AOS-CX Switches to the latest version released by HPE.
Who is affected by CVE-2026-23817?
CVE-2026-23817 affects users of HPE ArubaOS-CX in specific versions, including those from 10.06.0000 to 10.10.1180, 10.13.0000 to 10.13.1161, 10.16.0000 to 10.16.1030, and 10.17.0000 to 10.17.1001.
Can CVE-2026-23817 be exploited remotely?
Yes, CVE-2026-23817 can be exploited remotely by an unauthenticated attacker to redirect users to arbitrary URLs.
What is the impact of exploiting CVE-2026-23817?
The exploitation of CVE-2026-23817 could lead to phishing attacks as users might be redirected to malicious sites.