Multiple Vulnerabilities in HPE Aruba Networking Private 5G Core
18 August 2026
Attackers can exploit multiple vulnerabilities in HPE Aruba Networking Private 5G Core affecting third-party components Traefik and Grafana to spoof identities and escalate privileges. Patch promptly.
Background
HPE Aruba Networking has released a patch for HPE Aruba Networking Private 5G Core to address multiple security vulnerabilities in third-party components affecting Traefik (CVE-2026-54763) and Grafana (CVE-2026-33377).
These vulnerabilities have a Common Vulnerability Scoring System (CVSS v3.1) score of: CVE-2026-54763 at 8.8 and CVE-2026-33377 at 7.1, out of 10.
Impact
Successful exploitation of these vulnerabilities could lead to the following:
CVE-2026-54763: Due to improper handling of case sensitivity in the BasicAuth, DigestAuth, and ForwardAuth middlewares of Traefik, an authenticated attacker could inject underscore-variant headers to spoof identities or authorisation contexts on the affected backend system.
CVE-2026-33377: Due to improper access control in Grafana, an authenticated attacker with Editor-level write access could overwrite a dashboard not owned by them to escalate privileges on the affected dashboard.
Affected Products
These vulnerabilities affect the following products and versions:
CVE-2026-54763 (Traefik): versions prior to 2.11.51, 3.6.22, and 3.7.6
CVE-2026-33377 (Grafana): versions prior to 11.6.14, 12.2.8, 12.3.6, 12.4.3, and 13.0.1
Recommendations
Users and administrators of affected products are advised to update to the latest versions promptly.
References
https://nvd.nist.gov/vuln/detail/CVE-2026-54763 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-33377 (opens in new tab)
