CVE-2026-73789 PUBLISHED

Unauthenticated Insecure Parameter Manipulation allows Data Tampering In CPPM Web Interface

Assigner: hpe
Reserved: 13.08.2026 Published: 09.09.2026 Updated: 09.09.2026

A vulnerability in the web-based management interface of CPPM guest account management services could allow an unauthenticated remote attacker to manipulate account settings. Successful exploitation could allow an attacker to extend network access beyond policy limits, leading to unauthorized prolonged use of network resources.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 5.3

Product Status

Vendor Hewlett Packard Enterprise (HPE)
Product ClearPass Policy Manager (CPPM)
Versions Default: affected
  • affected from 6.12.0 to 6.12.8 (incl.)
  • affected from 6.11.0 to 6.11.14 (incl.)

Credits

  • 0x50d reporter

References