CVE-2026-73787
moderateAuthenticated command injection in HPE Aruba ClearPass Policy Manager (CPPM)
HPE Aruba ClearPass Policy Manager (CPPM) has a flaw in its web interface that lets an authenticated remote attacker access directory information on the underlying system and escalate that access to executing arbitrary operating system commands. The bug is triggered remotely over the network via the CPPM web UI, but the CVSS vector (PR:H) indicates the attacker must already hold high-privileged, effectively administrative, credentials. Successful exploitation yields full confidentiality, integrity, and availability impact on the host, i.e., administrative-level code execution on the appliance or virtual appliance hosting CPPM. Only organizations running ClearPass Policy Manager are affected; the available data does not specify which CPPM versions are vulnerable. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Watch for the HPE Aruba security advisory (CNA: [email protected]) and upgrade ClearPass Policy Manager to the fixed release it specifies, since affected/fixed versions are not listed in the data available here. Until patching, restrict access to the CPPM web interface to trusted management networks via firewall rules or VPN, and audit which accounts hold high-privilege (admin-level) CPPM credentials, since those are the prerequisite for exploitation. Check internet-exposed ClearPass guest/admin interfaces in your environment and monitor for any signs of exploitation.
| HPE (Aruba) ClearPass Policy Manager (CPPM) web interface | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information on a vulnerable system. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.