GPU VulnDB

Database/Control plane, storage & DevOps

HPE OneView: remotely exploitable session hijacking against the infrastructure management console

CVSS 8.2CVE-2026-76718Control plane, storage & DevOps+1 more CVEscurated

Impact

HPE assigned two ids in one advisory to remotely exploitable flaws in OneView that allow session hijacking, data theft or other unauthorized actions; both score 8.2 with the same vector, so this entry covers the pair (CVE-2026-76718 and CVE-2026-76719). OneView is the management plane for HPE server, storage and fabric hardware - including the ProLiant and Apollo/Cray chassis that host GPU nodes - so an attacker who rides an administrator's authenticated session inherits the ability to reconfigure, re-provision or power-cycle fleet hardware. The scope-changed vector and requirement for user interaction point at a browser-delivered attack against a logged-in operator rather than direct unauthenticated access. Confidentiality impact is high and integrity low, so expect credential and inventory exposure plus some ability to act as the admin.

Who can reach it

Network: an unauthenticated attacker who can get a logged-in OneView administrator to interact with attacker-controlled content. No OneView credentials are needed by the attacker; the privilege comes from the victim's session.

What to do

Apply the OneView update named in HPE advisory HPESBGN05140 and restart the appliance - a management-appliance upgrade, not host maintenance, so no GPU nodes are drained. Verify the fixed version in the advisory against your deployed release before scheduling. In the meantime, keep the OneView console off any general-purpose network, restrict it to the management VLAN, and have administrators use a dedicated browser session for it.

Also covers 1 CVE

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2026-76719

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.