CVE-2026-73788 PUBLISHED

Privilege Escalation in ClearPass OnGuard Agent

Assigner: hpe
Reserved: 13.08.2026 Published: 09.09.2026 Updated: 09.09.2026

A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own privileges on a vulnerable ClearPass OnGuard deployment. Successful exploitation could allow an attacker to obtain root privileges, leading to potentially unauthorized operation of the vulnerable system.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS Score: 6.5

Product Status

Vendor Hewlett Packard Enterprise (HPE)
Product ClearPass Policy Manager (CPPM)
Versions Default: affected
  • affected from 6.12.0 to 6.12.8 (incl.)
  • affected from 6.11.0 to 6.11.14 (incl.)

Credits

  • n3k reporter

References