CVE-2026-79809highCWE-22

CVE-2026-79809: high-severity vulnerability in Hewlett Packard Enterprise (HPE) ClearPass…

Unauthenticated Path Traversal in ClearPass Policy Manager API Endpoint Leads to Authorization Bypass

Published · Updated

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.3epss 0.2%
exploitation probability
0.2%top 86% of all CVEs
observed exploitation
nono source reports it
An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability allows an unauthenticated remote attacker to influence authorization decisions and be assigned an unintended role.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L