CVE-2026-79803: high-severity vulnerability in Hewlett Packard Enterprise (HPE) ClearPass…
Authenticated Command Injection Leading to Privilege Escalation in ClearPass Policy Manager API
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8epss 0.7%
exploitation probability
0.7%top 47% of all CVEs
observed exploitation
nono source reports it
A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploitation could allow an authenticated remote attacker to escalate privileges and gain administrative control of the affected system.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Hewlett Packard Enterprise (HPE) · ClearPass Policy Manager (CPPM)Related CVEs — Hewlett Packard Enterprise (HPE) ClearPass…
In the same product, most dangerous first.
CVE-2026-79802HIGHCommand Injection Vulnerability in the ClearPass Policy Manager Client SoftwareEPSS 1.1%CVE-2026-73769HIGHAuthenticated Remote Code Execution in CPPM Web InterfaceEPSS 1.1%CVE-2026-73787HIGHAuthenticated Arbitrary File Write allows Remote Code Execution via CPPM Web InterfaceEPSS 0.8%CVE-2026-79801CRITICALUnauthenticated Missing Integrity Verification allows Remote Code Execution in ClearPass Policy Manager Client AgentEPSS 0.6%CVE-2026-79815MEDIUMAuthenticated Command Injection Vulnerability in the ClearPass Policy Manager OnGuard AgentEPSS 0.6%CVE-2026-73786HIGHUnauthenticated Network-Based Denial of Service in CPPM systemsEPSS 0.6%