Description
A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Instant On, only if certain preconditions outside of the attacker's control are met.
Published: 2026-09-29
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Assess Impact
AI Analysis

Impact

A local authenticated user with high privileges on HPE Networking Instant On can exploit a flaw in the underlying operating system to read protected data. The vulnerability allows access to information that an attacker could use to move laterally or compromise additional network services, but only if conditions outside the attacker’s control are met. This constitutes an information exposure weakness and could lead to confidentiality loss.

Affected Systems

The affected product is HPE Networking Instant On. No specific firmware or software versions are cited in the advisory, so all current releases should be reviewed against HPE’s support documentation.

Risk and Exploitability

The CVSS score of 4.1 indicates a moderate severity vulnerability. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog. The attack vector is local and requires authenticated access with high privileges. Because exploitation depends on external preconditions, the risk of impact may vary, but organizations should consider the potential for an attacker to gain data useful for further compromise.

Generated by OpenCVE AI on September 29, 2026 at 21:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Verify the firmware or operating system version of HPE Networking Instant On against HPE’s security advisories to determine if it is affected.
  • Restrict local accounts that have elevated privileges to the minimum necessary roles to reduce the ability to read sensitive data.
  • Implement network segmentation to isolate HPE devices from other critical network segments.
  • Monitor device logs for unusual queries or data exfiltration attempts that may indicate exploitation.

Generated by OpenCVE AI on September 29, 2026 at 21:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 29 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Instant On, only if certain preconditions outside of the attacker's control are met.
Title Authenticated Local Sensitive Information Disclosure in HPE Networking Instant On
References
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-29T19:28:53.320Z

Reserved: 2026-08-19T16:13:34.635Z

Link: CVE-2026-76735

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T20:17:25.890

Modified: 2026-09-29T21:39:02.570

Link: CVE-2026-76735

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T21:45:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor