ZeroHour

CVE-2026-73787

moderate

Authenticated command injection in HPE Aruba ClearPass Policy Manager (CPPM)

CVSS 3.1
7.2 high
EPSS
<1%p53
Published
()
Modified
AI analysis

HPE Aruba ClearPass Policy Manager (CPPM) has a flaw in its web interface that lets an authenticated remote attacker access directory information on the underlying system and escalate that access to executing arbitrary operating system commands. The bug is triggered remotely over the network via the CPPM web UI, but the CVSS vector (PR:H) indicates the attacker must already hold high-privileged, effectively administrative, credentials. Successful exploitation yields full confidentiality, integrity, and availability impact on the host, i.e., administrative-level code execution on the appliance or virtual appliance hosting CPPM. Only organizations running ClearPass Policy Manager are affected; the available data does not specify which CPPM versions are vulnerable. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.

What to do: Watch for the HPE Aruba security advisory (CNA: [email protected]) and upgrade ClearPass Policy Manager to the fixed release it specifies, since affected/fixed versions are not listed in the data available here. Until patching, restrict access to the CPPM web interface to trusted management networks via firewall rules or VPN, and audit which accounts hold high-privilege (admin-level) CPPM credentials, since those are the prerequisite for exploitation. Check internet-exposed ClearPass guest/admin interfaces in your environment and monitor for any signs of exploitation.

Affected
HPE (Aruba) ClearPass Policy Manager (CPPM) web interface
Estimated exposure
moderate≈5,000–15,000 internet-exposed CPPM web/admin interfaces (public scan estimates); larger internal installed base — Public internet-wide scans such as Shodan/Censys historically index on the order of thousands of exposed ClearPass web interfaces, and CPPM is deployed as per-enterprise NAC appliances rather than mass-market software, though most…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information on a vulnerable system. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.