Database/Control plane, storage & DevOps

HPE OneView: remotely exploitable session hijacking against the infrastructure management console
Impact
HPE assigned two ids in one advisory to remotely exploitable flaws in OneView that allow session hijacking, data theft or other unauthorized actions; both score 8.2 with the same vector, so this entry covers the pair (CVE-2026-76718 and CVE-2026-76719). OneView is the management plane for HPE server, storage and fabric hardware - including the ProLiant and Apollo/Cray chassis that host GPU nodes - so an attacker who rides an administrator's authenticated session inherits the ability to reconfigure, re-provision or power-cycle fleet hardware. The scope-changed vector and requirement for user interaction point at a browser-delivered attack against a logged-in operator rather than direct unauthenticated access. Confidentiality impact is high and integrity low, so expect credential and inventory exposure plus some ability to act as the admin.
Who can reach it
Network: an unauthenticated attacker who can get a logged-in OneView administrator to interact with attacker-controlled content. No OneView credentials are needed by the attacker; the privilege comes from the victim's session.
What to do
Apply the OneView update named in HPE advisory HPESBGN05140 and restart the appliance - a management-appliance upgrade, not host maintenance, so no GPU nodes are drained. Verify the fixed version in the advisory against your deployed release before scheduling. In the meantime, keep the OneView console off any general-purpose network, restrict it to the management VLAN, and have administrators use a dedicated browser session for it.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- GitLab CE/EE: unsanitized Markdown JSON table content induces state-changing requests as a targeted userCVE-2026-78252 · GitLab CE/EE (Markdown JSON table renderer)High
- Ceph RGW (SigV4 signature verifier): Anyone handed a single presigned PUT URL gets more authority than whoever signedNCVD-2026-039-ceph-rgw-sigv4-signature-verifie · Ceph RGW (SigV4 signature verifier)High
- Ceph MON (config-key store, MMonSubscribe handler): MULTI-TENANT ISOLATION AND HOST COMPROMISE: one craftedNCVD-2026-041-ceph-mon-config-key-store-mmonsu · Ceph MON (config-key store, MMonSubscribe handler)High
- Ceph MON (ceph-mon): The monitor accepts pool create/delete and snapshot operations from any authenticated user thatCVE-2018-10861 · Ceph MON (ceph-mon)High
- GlusterFS (brick, gfs3_mknod_req): A crafted mknod RPC traverses out of the volume and writes a file anywhere the brickCVE-2018-10926 · GlusterFS (brick, gfs3_mknod_req)High
- Cisco IOS XE MACsec Key Agreement (MKA over EAP-TLS): A logic error in MKA over EAP-TLS lets an unauthenticatedCVE-2018-15372 · Cisco IOS XE MACsec Key Agreement (MKA over EAP-TLS)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.