Skip to content
HPE Telco Service Activator Vulnerability Allows Access Control Bypass

HPE Telco Service Activator Vulnerability Allows Access Control Bypass

First seen 23 Feb 2026, 13:09 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

A vulnerability in HPE Telco Service Activator, reported on February 19, 2026, allows attackers to bypass access restrictions. The flaw is linked to improper input validation in the Undertow HTTP server core used by the product, specifically failing to validate the Host header.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 198d ago How this analysis works

Timeline

2026-02-19
Security Bulletin released addressing the vulnerability
2026-02-23
Articles published detailing the vulnerability

More articles in this cluster (4)

Following this threat?

Track Fortinet and CVE-2025-12543 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed