CVE-2026-73769 PUBLISHED

Authenticated Remote Code Execution in CPPM Web Interface

Assigner: hpe
Reserved: 13.08.2026 Published: 09.09.2026 Updated: 09.09.2026

A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.2

Product Status

Vendor Hewlett Packard Enterprise (HPE)
Product ClearPass Policy Manager (CPPM)
Versions Default: affected
  • affected from 6.12.0 to 6.12.8 (incl.)
  • affected from 6.11.0 to 6.11.14 (incl.)

Credits

  • Daniel Jensen (@dozernz) reporter

References