CVE Field Guide
About Us
CVE-2026-76720
PUBLISHED
HPE OneView - URL Redirect vulnerability
Assigner:
hpe
Reserved:
19.08.2026
Published:
29.09.2026
Updated:
29.09.2026
A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect.
Metrics
CVSS 3.1
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS Score:
4.3
CVSS score
4.3
Attack Vector
Network
Scope
Unchanged
Attack Complexity
Low
Confidentiality Impact
Low
Privileges Required
None
Integrity Impact
None
User Interaction
Required
Availability Impact
None
CVSS 3.1
Product Status
Vendor
Hewlett Packard Enterprise
Product
HPE OneView
Versions
Default:
affected
affected from 0 to 11.40 (excl.)
References
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn05140en_us&docLocale=en_US
Problem Types
CWE-601 URL redirection to untrusted site ('open redirect')
CWE
Impacts
CAPEC-439 Manipulation During Distribution