CVE-2026-79802: fallo de gravedad alta en Hewlett Packard Enterprise (HPE) ClearPass…
Command Injection Vulnerability in the ClearPass Policy Manager Client Software
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.8epss 1.1%
probabilidad de explotación
1.1%top 35% de las CVE
explotación observada
noninguna fuente lo reporta
A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted input to the affected software to execute arbitrary commands with elevated privileges on the affected host.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Productos afectados
Hewlett Packard Enterprise (HPE) · ClearPass Policy Manager (CPPM)CVEs relacionadas — Hewlett Packard Enterprise (HPE) ClearPass…
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-73769HIGHAuthenticated Remote Code Execution in CPPM Web InterfaceEPSS 1.1%CVE-2026-73787HIGHAuthenticated Arbitrary File Write allows Remote Code Execution via CPPM Web InterfaceEPSS 0.8%CVE-2026-79803HIGHAuthenticated Command Injection Leading to Privilege Escalation in ClearPass Policy Manager APIEPSS 0.7%CVE-2026-79801CRITICALUnauthenticated Missing Integrity Verification allows Remote Code Execution in ClearPass Policy Manager Client AgentEPSS 0.6%CVE-2026-79815MEDIUMAuthenticated Command Injection Vulnerability in the ClearPass Policy Manager OnGuard AgentEPSS 0.6%CVE-2026-73786HIGHUnauthenticated Network-Based Denial of Service in CPPM systemsEPSS 0.6%