CVE-2026-76720 PUBLISHED

HPE OneView - URL Redirect vulnerability

Assigner: hpe
Reserved: 19.08.2026 Published: 29.09.2026 Updated: 29.09.2026

A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor Hewlett Packard Enterprise
Product HPE OneView
Versions Default: affected
  • affected from 0 to 11.40 (excl.)

References

Problem Types

  • CWE-601 URL redirection to untrusted site ('open redirect') CWE

Impacts

  • CAPEC-439 Manipulation During Distribution