CVE-2026-73786 PUBLISHED

Unauthenticated Network-Based Denial of Service in CPPM systems

Assigner: hpe
Reserved: 13.08.2026 Published: 09.09.2026 Updated: 09.09.2026

A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attacker to cause instability and degrade performance of the vulnerable CPPM server.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor Hewlett Packard Enterprise (HPE)
Product ClearPass Policy Manager (CPPM)
Versions Default: affected
  • affected from 6.11.0 to 6.11.14 (incl.)

Credits

  • promasu reporter

References