ZeroHour

CVE-2026-73786

PoC large

Unauthenticated DoS in HPE Aruba ClearPass Policy Manager Web Interface

CVSS 3.1
7.5 high
EPSS
<1%p26
Published
()
Modified
AI analysis

CVE-2026-73786 is a denial-of-service flaw in the web-based management interface of HPE Aruba ClearPass Policy Manager (CPPM), HPE's network access control (NAC) platform. An unauthenticated remote attacker can trigger it by sending malicious requests to the vulnerable management interface, with no credentials or user interaction required. Successful exploitation degrades performance and causes instability of the CPPM server, impacting availability only — there is no confidentiality or integrity impact per the CVSS vector. Organizations running affected CPPM deployments are in scope, though the affected version ranges are not specified in the available advisory data. Exploitation has not been observed: the flaw is not in CISA's KEV and no public proof-of-concept is known.

What to do: Review whether your CPPM web management interface is reachable from untrusted networks and restrict access to trusted management networks or via VPN/firewall rules as an interim mitigation. Monitor the HPE-Aruba security advisory for the affected version ranges and patched releases (not included in this data) and apply the vendor update promptly once published, since no public PoC or in-the-wild exploitation is currently known.

Affected
HPE (Aruba) Aruba ClearPass Policy Manager (CPPM) — web-based management interface
Estimated exposure
largetens of thousands of CPPM deployments worldwide (enterprise appliances/virtual machines), with only a subset exposing the management interface to untrusted… — ClearPass is one of the most widely deployed enterprise NAC products across large enterprises, universities and healthcare networks, implying an installed base in the tens of thousands of servers, though the web management interface is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attacker to cause instability and degrade performance of the vulnerable CPPM server.

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.