By Divya
Publication Date: 2026-02-12 11:14:00
HPE Aruba Networking has issued a critical security advisory addressing multiple vulnerabilities in its private 5G core platform that could allow attackers to create unauthorized administrative accounts, interrupt services and access sensitive system information.
The flaws, tracked as CVE-2026-23595, CVE-2026-23596, CVE-2026-23597, and CVE-2026-23598, were discovered by Communications Security Establishment (CSE) and affect platform versions 1.24.3.0 to 1.24.3.3.
Critical Authentication Bypass Vulnerability
The most serious vulnerability, CVE-2026-23595, scored 8.8 on the CVSS scale and involves an authentication bypass in the application API.
This high severity flaw allows unauthenticated remote attackers to create privileged user accounts without any authorization.
| CVE ID | Vulnerability type | CVSS Score | Impact |
|---|---|---|---|
| CVE-2026-23595 | Authentication Bypass in Application API | 8.8 (High) | Creation of unauthorized administrative accounts, escalation of privileges |




