Description
A sensitive information disclosure vulnerability exists in the client software of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an attacker with local access to the affected system to obtain sensitive information.
Published: 2026-10-06
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: Local Sensitive Information Disclosure
Action: Patch Now
AI Analysis

Impact

The vulnerability allows an attacker who already has physical or local access to a system running the ClearPass client software to read sensitive information that the application handles. Because the flaw is not remotely exploitable, it does not grant broader network reach but can compromise local credentials, configuration data, or other privileged details that could assist in a larger compromise. The weakness corresponds to an information exposure flaw, where data that should remain confidential is inadvertently revealed to a local user.

Affected Systems

Hewlett Packard Enterprise’s ClearPass Policy Manager client software is affected. No specific version numbers are disclosed in the available data, so all releases of the client should be reviewed against vendor advisories to determine the applicability of this issue.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, and at the time of analysis no EPSS score is provided, suggesting that historical exploitation activity is not known. The vulnerability is not listed in CISA’s KEV catalog, which implies it has not yet been observed as part of a widespread exploitation campaign. The likely attack vector involves local physical or administrative access; an attacker would need to be able to log into or otherwise access the target system to read the exposed data. Because the flaw requires local access, the overall risk is limited to environments where compromised physical or user accounts are a concern. Nonetheless, the exposure of sensitive information can enable further attacks, such as credential theft or lateral movement, if an adversary applies the disclosed data in a broader campaign.

Generated by OpenCVE AI on October 6, 2026 at 22:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available HPE patch or update for the ClearPass Policy Manager client software.
  • Limit local physical and administrative access to systems running the ClearPass client, restricting use by privileged or trusted personnel only.
  • Review user privileges on affected machines and remove unnecessary local access rights, ensuring that only essential staff can log in.

Generated by OpenCVE AI on October 6, 2026 at 22:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description A sensitive information disclosure vulnerability exists in the client software of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an attacker with local access to the affected system to obtain sensitive information.
Title Local Disclosure of Sensitive Information in HPE Networking ClearPass Policy Manager Client Software
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-10-06T19:17:18.816Z

Reserved: 2026-08-25T14:46:40.580Z

Link: CVE-2026-79817

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:33.430

Modified: 2026-10-06T20:17:33.430

Link: CVE-2026-79817

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T23:00:08Z

Weaknesses

No weakness.