Description
A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which resumes without manual intervention.
Published: 2026-09-29
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Update Software
AI Analysis

Impact

A denial‑of‑service flaw exists in the HPE Networking Instant On API endpoint that can be leveraged by an authenticated attacker holding administrative rights. By exploiting this vulnerability, an adversary can temporarily halt the normal operation of the service, which will subsequently recover without manual intervention. The impact is confined to service availability and does not directly affect confidentiality or integrity.

Affected Systems

Hewlett Packard Enterprise’s Instant ON platform is affected. No specific firmware or software versions are listed in the advisory, so all releases of the product are potentially vulnerable.

Risk and Exploitability

The CVSS score of 4.9 indicates moderate severity. The EPSS score is not currently available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated administrative credentials, so the threat surface is limited to trusted users or compromised accounts. Because the attack vector involves API access, the likelihood of exploitation in the wild is low but not negligible, especially in environments where API authentication is weak or oversight exists.

Generated by OpenCVE AI on September 29, 2026 at 21:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Ensure the latest HPE Instant ON firmware or software is installed, as that contains the fix for the API endpoint flaw.
  • If an immediate patch is unavailable, restrict API access to a minimal set of trusted administrative accounts and enforce strict authentication controls.
  • Monitor API usage for unusual patterns and configure alerts for repeated or excessive requests that could indicate a denial‑of‑service attempt.

Generated by OpenCVE AI on September 29, 2026 at 21:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399

Tue, 29 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which resumes without manual intervention.
Title Authenticated Denial-of-Service Vulnerability in HPE Networking Instant On API Endpoint
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-29T19:28:51.090Z

Reserved: 2026-08-19T16:13:18.140Z

Link: CVE-2026-76733

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T20:17:25.627

Modified: 2026-09-29T21:39:02.570

Link: CVE-2026-76733

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T21:45:17Z

Weaknesses