Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

HPE Aruba Flaw Exposes Networking Devices to Privilege Escalation and DoS Attacks

HPE Aruba Networking has issued a security advisory regarding multiple vulnerabilities identified in its Private 5G Core Platform. These vulnerabilities could potentially allow attackers to create unauthorized administrative accounts, disrupt services,…

HPE Aruba Networking has issued a security advisory regarding multiple vulnerabilities identified in its Private 5G Core Platform. These vulnerabilities could potentially allow attackers to create unauthorized administrative accounts, disrupt services, and access sensitive system information.

The vulnerabilities are tracked as CVE-2026-23595, CVE-2026-23596, CVE-2026-23597, and CVE-2026-23598. They affect platform versions 1.24.3.0 through 1.24.3.3, as discovered by the Communications Security Establishment (CSE).

Critical Authentication Bypass Vulnerability

The most severe issue, CVE-2026-23595, has been assigned a CVSS score of 8.8. It involves an authentication bypass in the application API, allowing unauthenticated remote attackers to create privileged user accounts.

CVE ID Vulnerability Type CVSS Score Impact

CVE-2026-23595 Authentication Bypass in Application API 8.8 (High) Unauthorized administrative account creation, privilege escalation

CVE-2026-23596 Improper Access Control in Management API 6.5 (Medium) Service disruption, denial of service through forced restarts

HPE Aruba Networking has issued a security advisory regarding multiple vulnerabilities identified in its Private 5G Core Platform.
Madison Drake · Thehackingpost

CVE-2026-23597 Information Disclosure in API Error Handling 6.5 (Medium) Exposure of user accounts, roles, system configuration details

CVE-2026-23598 Information Disclosure in API Error Handling 6.5 (Medium) Exposure of internal services, workflows, and sensitive data

Successful exploitation could grant attackers administrative access, allowing them to modify system configurations and manipulate sensitive data, potentially leading to persistent control over the network infrastructure. The vulnerabilities can be exploited with adjacent network access and do not require user interaction, posing a significant risk in corporate or industrial environments.

CVE-2026-23596, with a CVSS score of 6.5, allows unauthenticated attackers to trigger service restarts via improper access control in the management API, potentially disrupting critical networking services and impacting system availability.

Advertisement

CVE-2026-23597 and CVE-2026-23598 involve information disclosure through API error handling flaws, which could lead to attackers obtaining details about user accounts, roles, system configurations, and internal service workflows.

These vulnerabilities affect only HPE Aruba Networking Private 5G Core versions 1.24.3.0 to 1.24.3.3. Versions 1.24.2.2 and below, as well as version 1.25.1.0 and above, are not impacted.

Organizations using the affected versions are strongly advised to upgrade to version 1.25.1.0 or later to mitigate these security risks. The necessary patches are available through HPE's Enterprise License portal at myenterpriselicense.hpe.com. No workarounds exist, so patching remains the only effective defense strategy.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories