GPU VulnDB

Database/Control plane, storage & DevOps

HPE OneView: remotely triggerable URL redirect in the management console

CVSS 4.3CVE-2026-76720Control plane, storage & DevOpscurated

Impact

A vulnerability in HPE OneView can be exploited remotely to cause a URL redirect. On its own this is low severity (4.3, low confidentiality impact only), but OneView is the management console for HPE server and chassis hardware underneath GPU fleets, and an open redirect on a trusted management hostname is the standard first stage for phishing an infrastructure administrator into handing over a session - the same administrator whose session the higher-severity flaws in this advisory target. Treat it as a credibility lever against operators rather than a direct compromise of the appliance.

Who can reach it

Network, unauthenticated, but requires an operator to follow the crafted link. Anyone who can reach the OneView web interface - or craft a link to it for someone who can - can trigger the redirect.

What to do

Covered by the same OneView update as the other issues in HPE advisory HPESBGN05140; apply it and restart the appliance. No host or firmware maintenance is involved. Check the advisory for the fixed version applicable to your release.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.