Description
A vulnerability in an API interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to obtain sensitive information from the affected system.
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

An authentication bypass flaw exists in the API interface of ClearPass Policy Manager. The vulnerability allows a remote attacker to bypass existing authentication controls and access the API without credentials. Successful exploitation can lead to the disclosure of sensitive information stored or processed by the system.

Affected Systems

The affected product is Hewlett Packard Enterprise’s ClearPass Policy Manager. No specific version numbers are disclosed in the data, but any instance exposing the vulnerable API should be considered potentially impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and no EPSS score is available, so the exploitation likelihood is unknown. The vulnerability is not currently listed in the CISA KEV catalog. An attacker would need to identify the exposed API endpoint and send unauthenticated requests; the vulnerability does not require local or privileged access, implying a broad attack surface over the network.

Generated by OpenCVE AI on October 6, 2026 at 22:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch or upgrade ClearPass Policy Manager to a fixed version.
  • Restrict network access to the API by firewalling or segmenting the management network.
  • Enforce authentication on API endpoints, such as requiring token‑based or HTTPS‑only access.
  • Enable logging and monitoring for suspicious API activity to detect potential abuse.

Generated by OpenCVE AI on October 6, 2026 at 22:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-287

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in an API interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to obtain sensitive information from the affected system.
Title Authentication Bypass in the API Interface Allows Unauthorized Information Disclosure in ClearPass Policy Manager
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-10-06T19:17:19.720Z

Reserved: 2026-08-25T14:46:40.580Z

Link: CVE-2026-79818

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:33.550

Modified: 2026-10-06T20:17:33.550

Link: CVE-2026-79818

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T23:00:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-287

    Improper Authentication