Description
A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
Published: 2026-09-09
Score: 7.2 High
EPSS: 1.1% Low
KEV: No
Impact: Remote code execution
Action: Apply Fix
AI Analysis

Impact

A flaw in the web-based management interface of Hewlett Packard Enterprise ClearPass Policy Manager lets an authenticated attacker run arbitrary operating-system commands, enabling remote code execution. The weakness is tied to OS command injection (CWE-78). The damage potential is to gain full control of the underlying host, compromising confidentiality, integrity, and availability of services running on it.

Affected Systems

All deployments of Hewlett Packard Enterprise ClearPass Policy Manager that expose the web interface are affected; no specific patch level is listed, so the risk applies across versions until a security update is applied.

Risk and Exploitability

The CVSS score of 7.2 demonstrates a high severity level, while the EPSS score of less than 1% suggests that widespread exploitation is unlikely at the present time. The vulnerability is not recorded in CISA's KEV catalog. Successful exploitation requires valid administrative credentials—once authenticated, the attacker can execute arbitrary commands through the exposed web interface, as inferred from the description of a web-based management interface flaw.

Generated by OpenCVE AI on September 10, 2026 at 23:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Download and install the HPE ClearPass Policy Manager security update that addresses the remote code execution flaw.
  • Restrict access to the web-based management interface, allowing only trusted IP ranges or VPN connections.
  • Enforce strong passwords and enable multi-factor authentication for all administrative accounts.

Generated by OpenCVE AI on September 10, 2026 at 23:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) clearpass Policy Manager (cppm)
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) clearpass Policy Manager (cppm)

Thu, 10 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-94

Thu, 10 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-94

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
Title Authenticated Remote Code Execution in CPPM Web Interface
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Hewlett Packard Enterprise (hpe) Clearpass Policy Manager (cppm)
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-11T03:56:32.855Z

Reserved: 2026-08-13T16:38:49.645Z

Link: CVE-2026-73769

cve-icon Vulnrichment

Updated: 2026-09-10T14:04:24.116Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T20:20:33.360

Modified: 2026-09-11T04:17:49.273

Link: CVE-2026-73769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:00:07Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')