Skip to content
TrustList
News

HPE OneView before 11.40 has a cross-site scripting flaw that allows session hijacking: update to 11.40

Editorial

By TrustList Editorial

HPE published CVE-2026-76719 (rated 8.2) and CVE-2026-76720 (4.3) on 29 September 2026: a cross-site scripting flaw that can lead to session hijacking and an open redirect in HPE OneView before 11.40. Update the appliance to 11.40.

About HPE OneView before 11.40 has a cross-site scripting flaw that allows session hijacking: update to 11.40

HPE OneView before 11.40 has a cross-site scripting flaw that allows session hijacking: update to 11.40

2 October 2026 — Hewlett Packard Enterprise published two vulnerabilities in HPE OneView, its software for managing servers, storage and networking in the data centre, on 29 September 2026. Both affect every OneView version before 11.40, on the Linux and appliance platforms, and both are fixed in 11.40.

Not yet independently verified. The details come from the CVE records HPE itself published; HPE’s bulletin HPESBGN05140 needs a browser session and was not read, and no independent report was found. No exploitation is known. We will update this when it can be confirmed, and remove this note.

The two flaws

  • CVE-2026-76719, rated 8.2 (high). HPE says the vulnerability "may be exploited remotely to perform session hijacking, data theft or other unauthorized actions". The score's vector shows it can be reached over the network without an account, but needs a user to take an action, such as an administrator opening a crafted link; the impact can cross into other components.
  • CVE-2026-76720, rated 4.3 (medium). A URL redirection to an untrusted site, the kind of flaw used to make phishing links look as if they point at a trusted console.

The public CVE records show no known exploitation.

Why an infrastructure console matters

OneView administrators can provision, reconfigure and power-cycle physical servers and change firmware across a whole estate. A hijacked administrator session in that console is effectively control of the hardware layer, below the operating systems and the security tools that run on them.

What to do

  • Update every OneView appliance to 11.40. Check the version in the appliance settings; read HPE bulletin HPESBGN05140 for the upgrade path from your release.
  • Keep the console off general networks: reach it only from a management network or jump host.
  • Warn administrators about links that point at the OneView console, especially in email and chat, until the update is done.
  • Review console sessions and audit logs for sign-ins and changes nobody recognises.
  • If a partner manages your HPE estate, ask when the update will be applied.

Sources

Categories & features