HPE OneView before 11.40 has a cross-site scripting flaw that allows session hijacking: update to 11.40
EditorialBy TrustList Editorial
HPE published CVE-2026-76719 (rated 8.2) and CVE-2026-76720 (4.3) on 29 September 2026: a cross-site scripting flaw that can lead to session hijacking and an open redirect in HPE OneView before 11.40. Update the appliance to 11.40.
- Cybersecurity
- Vulnerability Management
- Patch Management
- Data Center
- +1 more
About HPE OneView before 11.40 has a cross-site scripting flaw that allows session hijacking: update to 11.40
HPE OneView before 11.40 has a cross-site scripting flaw that allows session hijacking: update to 11.40
2 October 2026 — Hewlett Packard Enterprise published two vulnerabilities in HPE OneView, its software for managing servers, storage and networking in the data centre, on 29 September 2026. Both affect every OneView version before 11.40, on the Linux and appliance platforms, and both are fixed in 11.40.
Not yet independently verified. The details come from the CVE records HPE itself published; HPE’s bulletin HPESBGN05140 needs a browser session and was not read, and no independent report was found. No exploitation is known. We will update this when it can be confirmed, and remove this note.
The two flaws
- CVE-2026-76719, rated 8.2 (high). HPE says the vulnerability "may be exploited remotely to perform session hijacking, data theft or other unauthorized actions". The score's vector shows it can be reached over the network without an account, but needs a user to take an action, such as an administrator opening a crafted link; the impact can cross into other components.
- CVE-2026-76720, rated 4.3 (medium). A URL redirection to an untrusted site, the kind of flaw used to make phishing links look as if they point at a trusted console.
The public CVE records show no known exploitation.
Why an infrastructure console matters
OneView administrators can provision, reconfigure and power-cycle physical servers and change firmware across a whole estate. A hijacked administrator session in that console is effectively control of the hardware layer, below the operating systems and the security tools that run on them.
What to do
- Update every OneView appliance to 11.40. Check the version in the appliance settings; read HPE bulletin HPESBGN05140 for the upgrade path from your release.
- Keep the console off general networks: reach it only from a management network or jump host.
- Warn administrators about links that point at the OneView console, especially in email and chat, until the update is done.
- Review console sessions and audit logs for sign-ins and changes nobody recognises.
- If a partner manages your HPE estate, ask when the update will be applied.
Sources
- CVE record CVE-2026-76719 (assigned by HPE) — 29 September 2026
- CVE record CVE-2026-76720 (assigned by HPE) — 29 September 2026
- HPE security bulletin HPESBGN05140 — 29 September 2026
Categories & features
- Cybersecurity
- Vulnerability Management
- Patch Management
- Data Center
- IT Management Software
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.