ZeroHour

CVE-2026-23595

CVSS 3.1
8.8 high
EPSS
<1%p22
Published
()
Modified
Description

An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability to create privileged user accounts. Successful exploitation could allow an attacker to gain administrative access, modify system configurations, and access or manipulate sensitive data.

Vendors
hpe
Products
aruba networking private 5g core
Weakness
CWE-284
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.