Description
A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
Published: 2026-09-09
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Remote code execution
Action: Apply Fix
AI Analysis

Impact

The vulnerability resides in the web‑based management interface of ClearPass Policy Manager and permits an authenticated remote attacker to run arbitrary operating‑system commands. Successful exploitation gives the attacker full control of the system, representing a code‑execution attack layered on a weakness in authentication handling.

Affected Systems

Hewlett Packard Enterprise’s ClearPass Policy Manager is the affected product. No specific version numbers are listed in the advisory, so all installations of the web interface remain at risk until patched.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity. EPSS is not available and the issue is not on the CISA KEV list, suggesting limited documented exploitation. However, the requirement for authenticated access means attackers must compromise credentials first, but once obtained, they can execute arbitrary code remotely. The risk remains significant for organizations that expose the management interface to broader networks or use default credentials.

Generated by OpenCVE AI on September 9, 2026 at 20:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the HPE ClearPass Policy Manager security update that addresses the remote code execution flaw.
  • Limit access to the web‑based management interface by allowing only trusted IPs or VPN connections.
  • Enforce robust passwords and enable multi‑factor authentication for all CPPM administrative accounts.

Generated by OpenCVE AI on September 9, 2026 at 20:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-94

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
Title Authenticated Remote Code Execution in CPPM Web Interface
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-09T19:13:20.453Z

Reserved: 2026-08-13T16:38:49.645Z

Link: CVE-2026-73769

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T20:20:33.360

Modified: 2026-09-09T20:20:33.360

Link: CVE-2026-73769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T21:00:12Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')