CVE-2026-79817: medium-severity vulnerability in Hewlett Packard Enterprise (HPE) ClearPass…
Local Disclosure of Sensitive Information in HPE Networking ClearPass Policy Manager Client Software
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.5epss 0.1%
exploitation probability
0.1%top 99% of all CVEs
observed exploitation
nono source reports it
A sensitive information disclosure vulnerability exists in the client software of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an attacker with local access to the affected system to obtain sensitive information.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
Hewlett Packard Enterprise (HPE) · ClearPass Policy Manager (CPPM)Related CVEs — Hewlett Packard Enterprise (HPE) ClearPass…
In the same product, most dangerous first.
CVE-2026-79802HIGHCommand Injection Vulnerability in the ClearPass Policy Manager Client SoftwareEPSS 1.1%CVE-2026-73769HIGHAuthenticated Remote Code Execution in CPPM Web InterfaceEPSS 1.1%CVE-2026-73787HIGHAuthenticated Arbitrary File Write allows Remote Code Execution via CPPM Web InterfaceEPSS 0.8%CVE-2026-79803HIGHAuthenticated Command Injection Leading to Privilege Escalation in ClearPass Policy Manager APIEPSS 0.7%CVE-2026-79801CRITICALUnauthenticated Missing Integrity Verification allows Remote Code Execution in ClearPass Policy Manager Client AgentEPSS 0.6%CVE-2026-79815MEDIUMAuthenticated Command Injection Vulnerability in the ClearPass Policy Manager OnGuard AgentEPSS 0.6%