SB2026081241 - Multiple vulnerabilities in HPE Aruba Networking Private 5G Core
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Improper Handling of Case Sensitivity (CVE-ID: CVE-2026-54763)
CWE-ID: CWE-178 - Improper Handling of Case Sensitivity
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to spoof identity or authorization context.
The vulnerability exists due to improper handling of case sensitivity in BasicAuth, DigestAuth, ForwardAuth, and ingress-nginx snippet authResponseHeaders handling when processing underscore-variant identity headers. A remote user can send a specially crafted request with underscore-variant headers to spoof identity or authorization context.
In the ForwardAuth authResponseHeaders path, exploitation does not require credentials.
2) Improper access control (CVE-ID: CVE-2026-33377)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges on a specific dashboard.
The vulnerability exists due to improper access control in the dashboard import functionality when importing a dashboard with write access to an existing dashboard. A remote user can overwrite a dashboard not owned by them to escalate privileges on that specific dashboard.
The user must have write access to the dashboard to exploit this issue.
Remediation
Install update from vendor's website.