Sceawere
Vulnerability Detail
CVE-2026-76719UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
HPE OneView Remote Session Hijacking
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 15h ago
- Vendor
- Hewlett Packard Enterprise
- Product
- HPE OneView
- Attack Type
- CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-09-29T10:17:11.920Z",
"pubdate": "2026-09-29T10:17:11.920Z",
"executiveSummary": "HPE OneView is susceptible to a critical security vulnerability that facilitates remote session hijacking, unauthorized data exfiltration, and execution of arbitrary actions within the management interface.\nThe vulnerability pertains to flaws in session management or authentication state handling, which allows an unauthenticated or low-privileged remote attacker to compromise established user sessions.\nBy successfully exploiting this weakness, an attacker can bypass standard authentication controls, effectively masquerading as a legitimate administrative user to access sensitive infrastructure data, modify configurations, or perform unauthorized administrative commands.\nThe scope of impact includes potential loss of confidentiality, integrity, and availability of managed HPE hardware environments.\nThe risk is severe as the vulnerability can be exploited remotely over the network without requiring local access to the appliance. Successful exploitation leverages the trust relationship established by existing, active sessions, granting the attacker the same permissions and privileges held by the hijacked user account.\nOrganizations utilizing HPE OneView are at risk of complete management platform compromise if protective measures or vendor-supplied patches are not promptly applied.",
"technicalDetails": "The vulnerability resides in the core session handling architecture of HPE OneView, where the mechanisms designed to bind user sessions to client identity are insufficient or improperly implemented.\nRoot cause analysis indicates a failure in session validation or token management, which allows an attacker to intercept, predict, or manipulate the session identifier associated with an authenticated user's connection to the management console.\nThe attack flow typically initiates with the attacker identifying a target active session, often through network-based interception (e.g., man-in-the-middle) or by exploiting weaknesses in the session token generation entropy and validation logic.\nOnce the session identifier is obtained, the attacker injects the hijacked token into their own client-side HTTP requests, effectively bypassing subsequent authentication checks by the HPE OneView server.\nBecause the application relies on the presence of a valid session cookie or token rather than continuous re-authentication for each sensitive request, the server incorrectly validates the attacker’s unauthorized requests as originating from the legitimate user's context.\nThe affected components are the web management interface and the underlying session management service within HPE OneView, which fail to cryptographically secure session identifiers against theft or unauthorized reuse.\nExploitation does not necessarily require administrative privileges prior to the attack, provided the attacker can gain access to an active session token. Exposure is network-wide, permitting any actor with reachability to the HPE OneView management port to initiate the attack sequence.\nPost-exploitation impact is critical; an attacker can perform any action available to the hijacked user, including the modification of managed system parameters, deployment of malicious configurations, exfiltration of sensitive configuration data, or the creation of new backdoors to ensure persistent, unauthorized access to the environment.\nThe vulnerability highlights a lack of robust session binding, such as failing to tie sessions strictly to the originating source IP address or implementing insufficient timeout and rotation policies for session tokens.\nWithout remediation, the system remains vulnerable to sophisticated session-based attacks, rendering standard password-based authentication bypassable for all active session users."
}