CVE-2026-23818: Open Redirect Vulnerability in HPE Aruba Networking Private 5G Core On-Prem

Published Apr 7, 2026
·
Updated

A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attacker-controlled server hosting a spoofed login page prompting the unsuspecting victim to give away their credentials, which could then be captured by the attacker, before being redirected back to the legitimate login page.

Affected Software

2 affected components
HPE Aruba Networking Private 5G Core On-Prem
HPE Aruba Networking Private 5G Core<1.25.3.1

Event History

Apr 7, 2026
CVE Published
via MITRE·12:18 PM
Data Sourced
via MITRE·12:18 PM
DescriptionSeverity
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-23818?

CVE-2026-23818 is considered a medium severity vulnerability due to its potential exploitation via open redirect attacks.

2

How does CVE-2026-23818 impact HPE Aruba Networking Private 5G Core On-Prem?

CVE-2026-23818 allows attackers to redirect users to malicious sites through the compromised login flow.

3

How do I fix CVE-2026-23818?

To fix CVE-2026-23818, update HPE Aruba Networking Private 5G Core On-Prem to the latest version above 1.25.3.1.

4

What are the symptoms of exploitation of CVE-2026-23818?

Exploitation of CVE-2026-23818 may result in users being redirected to unintended or malicious URLs during the login process.

5

Are there any workarounds for CVE-2026-23818?

Temporary workarounds for CVE-2026-23818 may include disabling certain features in the GUI that allow redirects.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203