Description
An authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713
Published: 2026-10-08
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Unauthorized Access via Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

An authentication bypass flaw in HPE Intelligent Management Center allows attackers to gain access without valid credentials. The vulnerability exploits an improper authorization check, enabling the attacker to obtain the same privileges as a legitimate user and potentially alter system configuration or data. This weakness can compromise the confidentiality, integrity, and availability of managed resources.

Affected Systems

Hewlett Packard Enterprise’s HPE Intelligent Management Center is affected in all releases prior to version 7.3 E0713. Any deployment using those versions is vulnerable and requires remediation.

Risk and Exploitability

The CVSS score of 9.1 marks this as a critical issue. Although no EPSS data is available and the vulnerability is not listed in CISA KEV, the risk of exploitation remains significant. The likely attack vector is remote across the management interface, where an attacker can craft a request to bypass the authentication mechanism and gain full system control. The ease of exploitation and the high impact warrant urgent attention.

Generated by OpenCVE AI on October 8, 2026 at 22:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade HPE Intelligent Management Center to version 7.3 E0713 or later to eliminate the authentication bypass flaw.
  • If an upgrade cannot be performed immediately, restrict all external access to the iMC console by firewalling the management port and limiting connectivity to trusted internal networks.
  • Enable multi‑factor authentication and monitor authentication logs for anomalous activity to reduce the window of exploitation.

Generated by OpenCVE AI on October 8, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 23:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in HPE Intelligent Management Center Before v7.3 E0713
Weaknesses CWE-285

Thu, 08 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-10-08T20:37:57.878Z

Reserved: 2026-08-25T14:47:15.582Z

Link: CVE-2026-79842

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T21:18:03.457

Modified: 2026-10-08T21:26:32.080

Link: CVE-2026-79842

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T23:00:15Z

Weaknesses