HPE Telco Service Activator Vulnerability Allows Access Control Bypass

HPE Telco Service Activator Vulnerability Allows Access Control Bypass

First seen 23 Feb 2026, 13:09 UTC GbhackersCybersecuritynewsCxtodayCyberpress 79% similarity 31.9

Article Content

Browse articles
ThreatCluster

A vulnerability in HPE Telco Service Activator, reported on February 19, 2026, allows attackers to bypass access restrictions. The flaw is linked to improper input validation in the Undertow HTTP server core used by the product, specifically failing to validate the Host header.

ThreatCluster AI How this analysis works

Timeline

2026-02-19
Security Bulletin released addressing the vulnerability
2026-02-23
Articles published detailing the vulnerability

Community

Browse all →