CVE-2026-73787 PUBLISHED

Authenticated Arbitrary File Write allows Remote Code Execution via CPPM Web Interface

Assigner: hpe
Reserved: 13.08.2026 Published: 09.09.2026 Updated: 09.09.2026

A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information on a vulnerable system. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.2

Product Status

Vendor Hewlett Packard Enterprise (HPE)
Product ClearPass Policy Manager (CPPM)
Versions Default: affected
  • affected from 6.11.0 to 6.11.14 (incl.)

Credits

  • Luke Young (@bored_engineer) reporter

References