CVE-2026-76709 PUBLISHED

Unauthenticated Remote Arbitrary File Write Vulnerability in HPE Networking Analytics and Location Engine (ALE)

Assigner: hpe
Reserved: 19.08.2026 Published: 22.09.2026 Updated: 23.09.2026

A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain unauthorized write access to the file system with elevated privileges, potentially resulting in full system compromise.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Hewlett Packard Enterprise (HPE)
Product ALE
Versions Default: affected
  • affected from 0.0.0.0 to 5.0.0.0 (incl.)

Credits

  • Internal security research (HPE Networking). reporter

References