HPE Aruba Flaw Exposes Networking Devices to Privilege Escalation and DoS Attacks

HPE Aruba Flaw Exposes Networking Devices to Privilege Escalation and DoS Attacks

By Divya
Publication Date: 2026-02-12 11:14:00

HPE Aruba Networking has issued a critical security advisory addressing multiple vulnerabilities in its private 5G core platform that could allow attackers to create unauthorized administrative accounts, interrupt services and access sensitive system information.

The flaws, tracked as CVE-2026-23595, CVE-2026-23596, CVE-2026-23597, and CVE-2026-23598, were discovered by Communications Security Establishment (CSE) and affect platform versions 1.24.3.0 to 1.24.3.3.

Critical Authentication Bypass Vulnerability

The most serious vulnerability, CVE-2026-23595, scored 8.8 on the CVSS scale and involves an authentication bypass in the application API.

This high severity flaw allows unauthenticated remote attackers to create privileged user accounts without any authorization.

CVE IDVulnerability typeCVSS ScoreImpact
CVE-2026-23595Authentication Bypass in Application API8.8 (High)Creation of unauthorized administrative accounts, escalation of privileges