Sceawere
Vulnerability Detail
CVE-2026-76720UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
HPE OneView URL Redirection Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 15h ago
- Vendor
- Hewlett Packard Enterprise
- Product
- HPE OneView
- Attack Type
- CWE-601 URL redirection to untrusted site ('open redirect')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-29T10:17:12.060Z",
"pubdate": "2026-09-29T10:17:12.060Z",
"executiveSummary": "A URL redirection vulnerability has been identified within HPE OneView, a comprehensive infrastructure management solution.\nThis vulnerability is classified as an Open Redirect, occurring when the application fails to adequately validate user-supplied input used for redirection targets.\nA remote, unauthenticated attacker can exploit this flaw by crafting a malicious URI that forces a victim's browser to navigate to an arbitrary, attacker-controlled external domain.\nWhile the vulnerability does not directly compromise the HPE OneView server or allow for remote code execution, it presents significant security risks, including the facilitation of phishing campaigns, credential theft, and the bypass of security controls that rely on domain-based trust.\nBy masquerading as a legitimate request from a trusted HPE OneView instance, attackers can deceive users into performing sensitive actions on malicious sites.\nOrganizations using HPE OneView are advised to assess their exposure, as this vulnerability leverages the trust associated with the enterprise environment to conduct secondary attacks against users.",
"technicalDetails": "The vulnerability resides in the request handling logic of HPE OneView, specifically where the application processes redirection parameters during authentication workflows or resource navigation.\nThe root cause is the lack of server-side validation or canonicalization of the 'destination' or 'redirect' URL parameters provided via HTTP GET or POST requests.\nThe application accepts a user-controlled string and incorporates it directly into the 'Location' header of the HTTP response without enforcing a whitelist of authorized domains or implementing host-based path validation.\nAttack flow: 1. An attacker identifies an endpoint in HPE OneView that accepts a redirect URL parameter (e.g., https://hpe-oneview-instance/login?redirect=...). 2. The attacker crafts a payload where the redirect parameter points to a malicious URL (e.g., https://attacker-controlled-site.com). 3. The attacker distributes this link to a target user, often disguised using URL shortening services or obfuscation techniques. 4. Upon clicking the link, the victim's browser sends a request to the legitimate HPE OneView server. 5. HPE OneView processes the request and issues an HTTP 302 or 301 redirect response, setting the 'Location' header to the attacker-supplied malicious URL. 6. The victim's browser automatically follows the redirect, navigating to the external malicious site under the false impression of remaining within the trusted infrastructure management environment.\nThe vulnerability is exposed via the network and does not require prior authentication, as the redirection often occurs at the application entry points or before session establishment. The impact is primarily client-side; however, the enterprise risk is high due to the potential for social engineering. By successfully hijacking the navigation flow, an attacker can present a spoofed login page that mimics the HPE OneView interface, effectively harvesting user credentials or session tokens if the attacker implements a man-in-the-middle or proxy-based credential capture mechanism.\nThe vulnerability persists due to the absence of regex-based URI validation or restrictive domain filtering within the affected function handlers, allowing for relative path traversal, protocol smuggling (e.g., 'javascript:' pseudo-protocols if not sanitized), and full-domain redirection."
}