HPE Networking ALE Flaws Let Hackers Bypass Security Controls and Compromise Systems
HPE fixed critical unauthenticated flaws in Networking ALE that enable credential abuse and arbitrary file writes.
Hewlett Packard Enterprise patched multiple flaws in HPE Networking Analytics and Location Engine (ALE) 5.0.0.0 and earlier, fixed in 5.1.0.0 under advisory HPESBNW05137. CVE-2026-76708 and CVE-2026-76709 are critical (CVSS 9.8) and remotely exploitable without authentication: one uses hard-coded default credentials, and the other allows arbitrary file writes. Additional high-severity issues include information disclosure, data injection, root file access, arbitrary command execution, and a man-in-the-middle flaw that could lead to remote code execution. HPE said it knew of no public exploit code or active exploitation and advised restricting management interfaces until customers upgrade.