SB2026081241 - Multiple vulnerabilities in HPE Aruba Networking Private 5G Core



SB2026081241 - Multiple vulnerabilities in HPE Aruba Networking Private 5G Core

Published: August 12, 2026

Security Bulletin ID SB2026081241
CSH Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Improper Handling of Case Sensitivity (CVE-ID: CVE-2026-54763)

CWE-ID: CWE-178 - Improper Handling of Case Sensitivity

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to spoof identity or authorization context.

The vulnerability exists due to improper handling of case sensitivity in BasicAuth, DigestAuth, ForwardAuth, and ingress-nginx snippet authResponseHeaders handling when processing underscore-variant identity headers. A remote user can send a specially crafted request with underscore-variant headers to spoof identity or authorization context.

In the ForwardAuth authResponseHeaders path, exploitation does not require credentials.


2) Improper access control (CVE-ID: CVE-2026-33377)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to escalate privileges on a specific dashboard.

The vulnerability exists due to improper access control in the dashboard import functionality when importing a dashboard with write access to an existing dashboard. A remote user can overwrite a dashboard not owned by them to escalate privileges on that specific dashboard.

The user must have write access to the dashboard to exploit this issue.


Remediation

Install update from vendor's website.