Overview
HPE has disclosed CVE-2026-76718, a high-severity cross-site scripting (XSS) vulnerability in HPE OneView, the company's converged infrastructure management platform used to provision and monitor servers, storage, and networking hardware across enterprise data centers. According to the NVD listing, published September 29, 2026, the flaw "can be exploited to allow remote session hijacking or other unauthorized actions."
The vulnerability carries a CVSS 3.1 score of 8.2 (High), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N — indicating a network-based attack with low complexity, no privileges required by the attacker, but requiring victim interaction (such as clicking a crafted link) against a logged-in OneView session. The Scope Changed (S:C) designation reflects that a successful attack can affect resources beyond the vulnerable component itself, consistent with a classic stored or reflected XSS chained into session-token theft.
CVE-2026-76718 was disclosed alongside a closely related sibling flaw, CVE-2026-76719 (also CVSS 8.2, XSS/session hijacking), and a lower-severity CVE-2026-76720 (open redirect, CVSS 4.3), all reportedly covered under HPE's security bulletin hpesbgn05140en_us, titled "HPE OneView, Multiple Vulnerabilities." Multiple third-party CVE aggregators tracking the bulletin list the affected range as OneView versions prior to 11.40, with 11.40 identified as the fixed release. Administrators should confirm exact remediation guidance against HPE's official bulletin at support.hpe.com, since the NVD record itself was still marked "Awaiting Analysis" as of this writing.
Technical Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-76718 |
| Severity | High |
| CVSS Score | 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N) |
| Attack Vector | Network |
| Authentication | Not required by the attacker |
| Privileges Required | None (PR:N) — victim must interact (UI:R) with a crafted request/link |
| CWE | CWE-79 — Improper Neutralization of Input During Web Page Generation (Cross-Site Scripting) |
| Component/Function | HPE OneView web management console (session handling) |
| Exploit Status | No confirmed in-the-wild exploitation as of September 30, 2026; not listed on CISA's KEV catalog |
How It Works
The vulnerability class
CVE-2026-76718 is a cross-site scripting (CWE-79) flaw in the OneView web console. Improperly neutralized input allows an attacker to inject script content that executes in the browser context of a legitimate, authenticated OneView administrator. Because OneView consoles typically hold broad control over physical infrastructure — server profiles, firmware baselines, storage volumes, and network fabric configuration — a hijacked admin session is a high-value target.
The attack chain
- An attacker crafts a malicious link or payload that exploits the unsanitized input path in OneView's web interface.
- The attacker delivers the payload to a target — typically an authenticated OneView administrator — via phishing, a malicious internal link, or a compromised page the admin is lured into visiting (
UI:Rin the CVSS vector). - When the victim's browser renders the crafted content inside an active OneView session, the injected script executes with the victim's session privileges.
- The Scope Changed rating indicates the malicious script can act beyond the vulnerable component, most plausibly by exfiltrating the OneView session token/cookie or issuing unauthorized API calls on the victim's behalf — enabling remote session hijacking or other unauthorized actions, per HPE's own description.
Why session hijacking on OneView specifically matters
OneView sits at the management plane for HPE Synergy, ProLiant, and other converged infrastructure. An attacker who hijacks an administrator session could potentially reconfigure server profiles, alter firmware/BIOS policies, manipulate virtual networking (Virtual Connect), or pivot to connected management interfaces (iLO) — all without needing valid credentials of their own.
Impact Assessment
| Impact Area | Description |
|---|---|
| Session/Credential Theft | A hijacked OneView session token can grant an attacker the same privileges as the logged-in administrator, without needing a password |
| Infrastructure Management Exposure | OneView governs server, storage, and network provisioning — unauthorized access could enable configuration tampering across managed hardware |
| Confidentiality | Rated High — session/cookie theft can expose sensitive management-plane data |
| Integrity | Rated Low per the CVSS vector, but a hijacked admin session could still be used to issue limited unauthorized actions |
| Availability | Rated None directly from this flaw, though downstream misuse of a hijacked session is not bounded by the CVSS score alone |
| Repeat Target | OneView has been a high-value target before — the critical, unauthenticated RCE CVE-2025-37164 (CVSS 10.0) was added to CISA's KEV catalog in January 2026 after mass exploitation by the RondoDox botnet, underscoring why every subsequent OneView advisory warrants prompt attention |
Recommendations
For HPE OneView administrators
- Identify all OneView instances in your environment and confirm their current version against HPE's advisory hpesbgn05140en_us.
- Upgrade to HPE OneView 11.40 or later, the version identified by tracking sources as containing the fix, after validating against HPE's official bulletin and change-management process.
- Restrict network access to the OneView management interface — place it behind a VPN or management-only network segment, never expose it directly to the internet.
- Review active OneView sessions and force re-authentication for administrative accounts following the upgrade.
For security teams
- Monitor OneView audit logs for anomalous administrative actions, unexpected configuration changes, or logins from unfamiliar sources.
- Treat OneView credentials and sessions as high-value assets — apply the same monitoring rigor used for domain admin or hypervisor management accounts.
- Correlate with the broader OneView threat history — given the CVE-2025-37164 KEV entry and active botnet targeting of OneView earlier in 2026, ensure detections cover both unauthenticated RCE attempts and session-hijacking indicators.
- Subscribe to HPE Security Bulletins for OneView and related converged-infrastructure products to catch follow-on advisories quickly.
For OneView users/administrators day-to-day
- Avoid clicking unsolicited or unfamiliar links while logged into the OneView console.
- Log out of OneView sessions when not actively managing infrastructure, rather than leaving authenticated tabs open indefinitely.
- Use a dedicated browser profile for infrastructure management consoles, separate from general web browsing.
Key Takeaways
- CVE-2026-76718 is a CVSS 8.2 cross-site scripting flaw (CWE-79) in HPE OneView, disclosed September 29, 2026, that can enable remote session hijacking of administrator sessions.
- The flaw requires no attacker authentication but does require victim interaction, consistent with a phishing-delivered or link-based XSS trigger.
- Affected versions are reported as HPE OneView prior to 11.40, with 11.40 identified as the fixed release under HPE bulletin hpesbgn05140en_us — confirm against HPE's official advisory before patching.
- It was disclosed alongside sibling flaws CVE-2026-76719 (same CVSS 8.2, session hijacking) and CVE-2026-76720 (open redirect, CVSS 4.3), suggesting a coordinated multi-issue OneView security bulletin.
- No confirmed active exploitation has been reported for CVE-2026-76718 as of this writing, but OneView has a recent history as an active exploitation target — CVE-2025-37164 (CVSS 10.0) landed on CISA's KEV catalog in January 2026 after botnet exploitation.
- Given OneView's control over physical server, storage, and network infrastructure, organizations should prioritize patching and session hygiene rather than waiting for confirmed in-the-wild exploitation.
Sources
- NVD — CVE-2026-76718
- HPE Support Center — Security Bulletin hpesbgn05140en_us
- The Hacker News — HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution
- The Hacker News — CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited
CosmicBytez Labs will update this advisory if HPE publishes additional technical detail or if active exploitation of CVE-2026-76718 is confirmed.