Description
A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information on a vulnerable system. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
Published: 2026-09-09
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A flaw in the ClearPass Policy Manager web interface permits an authenticated attacker to write arbitrary files, which can be leveraged to run arbitrary commands on the host operating system. This results in total loss of control over the affected system, enabling execution of malicious code. The weakness is rooted in inadequate input validation and insufficient privilege checks, allowing attackers to influence file system operations beyond their authorization.

Affected Systems

Hewlett Packard Enterprise’s ClearPass Policy Manager is vulnerable. No specific version ranges are listed, meaning all current releases may be affected until the vendor publishes a fix.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity. Because the vulnerability requires authentication, an attacker must possess valid credentials, but many administrators grant broad access. The EPSS score is not available, suggesting limited data on active exploitation. The vulnerability is not included in CISA’s KEV catalog, but the potential for remote code execution warrants immediate attention.

Generated by OpenCVE AI on September 9, 2026 at 20:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the vendor‑provided security update for ClearPass Policy Manager that addresses the arbitrary file write flaw.
  • Restrict web‑interface access to a narrow set of trusted administrators and enforce least‑privilege principals.
  • Continuously monitor system and web‑interface logs for unexpected file write activity or command execution attempts.

Generated by OpenCVE AI on September 9, 2026 at 20:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-272
CWE-94

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information on a vulnerable system. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
Title Authenticated Arbitrary File Write allows Remote Code Execution via CPPM Web Interface
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-09T19:14:18.443Z

Reserved: 2026-08-13T16:39:33.899Z

Link: CVE-2026-73787

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T20:20:33.607

Modified: 2026-09-09T20:20:33.607

Link: CVE-2026-73787

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T21:00:12Z

Weaknesses
  • CWE-272

    Least Privilege Violation

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')