Description
A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions.
Published: 2026-09-29
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Remote XSS allowing session hijacking and data theft
Action: Patch Now
AI Analysis

Impact

A cross‑site scripting flaw in HPE OneView allows an attacker to inject malicious scripts into the web interface. The vulnerability is classified as CWE-79, and if exploited it can lead to session hijacking, data theft, or execution of other unauthorized actions on the system.

Affected Systems

The affected product is Hewlett Packard Enterprise HPE OneView. No specific product version is listed in the advisory; the flaw appears to apply to all releases that contain the described XSS vulnerability.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity. EPSS data is not available, so the likelihood of exploitation is unknown. The vulnerability is not included in the CISA KEV catalog. The likely attack vector is remote, requiring an attacker to send crafted input to the OneView web interface from a network location that can access the management portal. No authentication step is required for the vulnerability to be triggered, but the attacker would need a user session or permission to execute the injected script.

Generated by OpenCVE AI on September 30, 2026 at 03:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the most recent HPE OneView security patch that addresses the XSS vulnerability.
  • Limit access to the OneView web interface to trusted users or IP ranges and enforce multi‑factor authentication.
  • Configure stringent Content Security Policy directives and ensure that all user‑supplied input is properly sanitized before rendering to prevent script execution.

Generated by OpenCVE AI on September 30, 2026 at 03:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions.
Title HPE OneView - Cross-site scripting vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-29T11:17:47.929Z

Reserved: 2026-08-19T16:12:51.872Z

Link: CVE-2026-76719

cve-icon Vulnrichment

Updated: 2026-09-29T11:12:11.762Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T10:17:11.920

Modified: 2026-09-29T21:39:02.570

Link: CVE-2026-76719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T03:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')