CVE-2026-79818: falha de média gravidade em Hewlett Packard Enterprise (HPE) ClearPass…
Authentication Bypass in the API Interface Allows Unauthorized Information Disclosure in ClearPass Policy Manager
Publicada em · Atualizada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.3epss 0.3%
probabilidade de exploração
0.3%top 81% das CVEs
exploração observada
nãonenhuma fonte reporta
A vulnerability in an API interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to obtain sensitive information from the affected system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Produtos afetados
Hewlett Packard Enterprise (HPE) · ClearPass Policy Manager (CPPM)CVEs relacionadas — Hewlett Packard Enterprise (HPE) ClearPass…
No mesmo produto, das mais perigosas para as menos.
CVE-2026-79802HIGHCommand Injection Vulnerability in the ClearPass Policy Manager Client SoftwareEPSS 1.1%CVE-2026-73769HIGHAuthenticated Remote Code Execution in CPPM Web InterfaceEPSS 1.1%CVE-2026-73787HIGHAuthenticated Arbitrary File Write allows Remote Code Execution via CPPM Web InterfaceEPSS 0.8%CVE-2026-79803HIGHAuthenticated Command Injection Leading to Privilege Escalation in ClearPass Policy Manager APIEPSS 0.7%CVE-2026-79801CRITICALUnauthenticated Missing Integrity Verification allows Remote Code Execution in ClearPass Policy Manager Client AgentEPSS 0.6%CVE-2026-79815MEDIUMAuthenticated Command Injection Vulnerability in the ClearPass Policy Manager OnGuard AgentEPSS 0.6%