Description
A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own privileges on a vulnerable ClearPass OnGuard deployment. Successful exploitation could allow an attacker to obtain root privileges, leading to potentially unauthorized operation of the vulnerable system.
Published: 2026-09-09
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unprivileged authenticated user can gain root privileges
Action: Assess Impact
AI Analysis

Impact

The vulnerability allows an authenticated remote attacker to execute processes with root privileges on a ClearPass OnGuard deployment. This elevation can lead to full control of the system, providing possibility to alter configurations, exfiltrate sensitive data and deploy malicious code. The weakness is an improper privilege escalation flaw.

Affected Systems

Hewlett Packard Enterprise ClearPass Policy Manager (CPPM) is affected. No specific version range was disclosed in the data, so all installations using the OnGuard agent should verify if they are running a vulnerable version.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. EPSS data is not available, so the current exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog, but it requires valid credentials to launch the attack, making it a risk for compromised user accounts or insider threat actors. An attacker could potentially move laterally after gaining root access.

Generated by OpenCVE AI on September 9, 2026 at 20:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact Hewlett Packard Enterprise for the latest security update or patch that addresses the privilege escalation in the OnGuard agent.
  • Implement strict access controls and enforce the principle of least privilege for all accounts that interact with ClearPass, reducing the potential impact of a credential compromise.
  • Regularly monitor system logs for abnormal privilege changes or unexpected root-level activity, and conduct periodic security audits to detect privilege misuse.

Generated by OpenCVE AI on September 9, 2026 at 20:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own privileges on a vulnerable ClearPass OnGuard deployment. Successful exploitation could allow an attacker to obtain root privileges, leading to potentially unauthorized operation of the vulnerable system.
Title Privilege Escalation in ClearPass OnGuard Agent
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-09T19:14:37.359Z

Reserved: 2026-08-13T16:39:33.899Z

Link: CVE-2026-73788

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T20:20:33.713

Modified: 2026-09-09T20:20:33.713

Link: CVE-2026-73788

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T21:00:12Z

Weaknesses
  • CWE-269

    Improper Privilege Management