Description
An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.
Published: 2026-09-29
Score: 3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply patch
AI Analysis

Impact

The vulnerability is a local path traversal flaw in the command line interface of HPE Networking Instant On. An authenticated administrator can craft commands that navigate outside the intended directories, allowing the modification of a restricted set of operating system files. The attacker’s actions can disrupt the normal operation of the service, effectively causing a denial‑of‑service condition for legitimate users.

Affected Systems

Affected systems include HPE Networking Instant On devices. No specific firmware or software version information is provided, so any deployment running the product may be susceptible until a patch is applied.

Risk and Exploitability

The CVSS score of 3 indicates low severity, and the EPSS score is unavailable. The flaw is not listed in the CISA KEV catalog. Exploitation requires administrative privileges on the CLI, so the threat is limited to users with those rights. Nonetheless, the ability to alter system files and interrupt service can remain a concern in environments where privileged users are numerous or oversight is weak.

Generated by OpenCVE AI on September 29, 2026 at 21:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the firmware or software update issued by HPE that fixes the path traversal issue.
  • Limit CLI administrative access to trusted administrators and enforce least privilege; consider disabling or restricting remote CLI if not required.
  • Enable logging of file modification events and monitor for anomalous changes to critical system files; apply strict file permissions to prevent tampering.

Generated by OpenCVE AI on September 29, 2026 at 21:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Tue, 29 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.
Title Authenticated Local Path Traversal Vulnerability Leads to Denial-of-Service in HPE Networking Instant On
References
Metrics cvssV3_1

{'score': 3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-29T19:28:56.780Z

Reserved: 2026-08-19T16:13:34.635Z

Link: CVE-2026-76737

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T20:17:26.150

Modified: 2026-09-29T21:39:02.570

Link: CVE-2026-76737

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T21:45:17Z

Weaknesses
  • CWE-20

    Improper Input Validation