Multiple Vulnerabilities in HPE Aruba Networking Private 5G Core
18 August 2026
Attackers could exploit multiple vulnerabilities in Traefik and Grafana to spoof identities and escalate privileges. Patch promptly.
Background
HPE has released security updates to address multiple vulnerabilities (CVE-2026-54763 and CVE-2026-33377) affecting Traefik and Grafana. These vulnerabilities have a Common Vulnerability Scoring System (CVSS v3.1) score of: CVE-2026-54763 at 8.8 and CVE-2026-33377 at 7.1, out of 10.
Impact
Successful exploitation of these vulnerabilities could lead to the following:
CVE-2026-54763: Due to improper handling of case sensitivity in the BasicAuth, DigestAuth, and ForwardAuth middlewares of Traefik, an authenticated attacker could inject underscore-variant headers to spoof identities or authorisation contexts on the affected backend system.
CVE-2026-33377: Due to improper access control in Grafana, an authenticated attacker with Editor-level write access could overwrite a dashboard not owned by them to escalate privileges on the affected dashboard.
Affected Products
These vulnerabilities affect the following products and versions:
CVE-2026-54763 (Traefik): versions prior to 2.11.51, 3.6.22, and 3.7.6
CVE-2026-33377 (Grafana): versions prior to 11.6.14, 12.2.8, 12.3.6, 12.4.3, and 13.0.1
Recommendations
Users and administrators of affected products are advised to update to the latest versions promptly.
References
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05119en_us&docLocale=en_US
