← Vulnerability feed

Vulnerability record · CVE-2026-23597 · published 17 February 2026

CVE-2026-23597: Hpe aruba networking private 5g core information exposure vulnerability

Hpe · Aruba Networking Private 5g Core

Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such as user accounts, roles, and system configuration, as well as to gain insight into internal services and workflows, increasing the risk of unauthorized access and elevated privileges when combined with other vulnerabilities.

6.5 CVSS 3.1 Medium EPSS 0.26% · top 84.2% CWE-200 · Information exposure
6.5CVSS 3.1 base score
0.26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such as user accounts, roles, and system configuration, as well as to gain insight into internal services and workflows, increasing the risk of unauthorized access and elevated privileges when combined with other vulnerabilities.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-23597 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2026-23818Hpe aruba networking private 5g core open redirect vulnerabilityA vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacke…EPSS 0.32%8.8CVE-2026-23595Hpe aruba networking private 5g core improper access control vulnerabilityAn authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vul…EPSS 0.31%6.5CVE-2026-23598Hpe aruba networking private 5g core error message information leak vulnerabilityVulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sens…EPSS 0.34%6.5CVE-2026-23596Hpe aruba networking private 5g core uncontrolled resource consumption vulnerabilityA vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful …EPSS 0.25%5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed7.5CVE-2026-20133Cisco Catalyst SD-WAN Manager insufficient file system restrictions expose dataCisco Catalyst SD-WAN Software has insufficient file system restrictions that let an attacker read sensitive files on the underlying operating system…KEVEPSS 32%analysed7.5CVE-2025-31125Vite dev server improper access control exposes arbitrary filesVite's dev server fails to restrict file access when a request uses the ?inline&import or ?raw?import query patterns, allowing content of files that …KEVEPSS 65%analysed5.5CVE-2026-20805Windows Desktop Window Manager information disclosureDesktop Windows Manager (DWM) in Microsoft Windows exposes sensitive information to an unauthorized actor, allowing a local attacker with existing ac…KEVEPSS 7.2%analysed

Source: NIST National Vulnerability Database (record CVE-2026-23597), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.