ZeroHour

CVE-2026-73769

large

Authenticated RCE in HPE Aruba ClearPass Policy Manager (CPPM) web interface

CVSS 3.1
7.2 high
EPSS
<1%p59
Published
()
Modified
AI analysis

CVE-2026-73769 is a remote code execution flaw in the web-based management interface of HPE Aruba ClearPass Policy Manager (CPPM). An attacker who has authenticated to the management interface with high-privilege (administrator-level) credentials, as indicated by the CVSS 'privileges required: high' metric, can trigger the flaw by sending a crafted request to the interface. Successful exploitation lets the attacker run arbitrary commands on the underlying operating system of the CPPM appliance or virtual appliance, giving full control of the host that authenticates and authorizes network users and devices. Organizations running vulnerable CPPM builds are affected; the specific vulnerable and fixed version ranges are not stated in the available data and must be taken from the HPE security advisory. There is no evidence of exploitation in the wild, no CISA KEV listing, and no known public proof-of-concept.

What to do: Upgrade ClearPass Policy Manager to the fixed release named in the HPE security advisory for CVE-2026-73769, since the affected version range is not listed here. Until patched, restrict access to the CPPM web management interface to trusted management networks or VPN, limit high-privilege accounts, and review admin and OS-level logs for unexpected commands or logins. Monitor HPE's advisory for updated version and mitigation details.

Affected
HPE (HPE Aruba Networking) ClearPass Policy Manager (CPPM) — web-based management interface
Estimated exposure
large≈10,000–50,000 enterprise deployments (tens of thousands of organizations run ClearPass; only a subset of admin interfaces, likely thousands, are… — ClearPass is HPE Aruba's widely deployed NAC platform used by large numbers of enterprise, education, and healthcare customers (typically multiple appliances per deployment), but because exploitation requires admin access to the management…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.