Unauthenticated Info Disclosure in HPE Networking Analytics and Location Engine (ALE)
AI analysis
CVE-2026-76717 is an unauthenticated information disclosure flaw (CWE-200) in the API of HPE's Analytics and Location Engine (ALE), an on-premises analytics appliance used with HPE (Aruba) campus wireless networks. A remote attacker with no credentials can send specially crafted input to a specific ALE API endpoint and retrieve sensitive user information, including password hashes, which could be cracked offline or reused to escalate further attacks. Any organization running an ALE deployment with the vulnerable API reachable is affected, and press coverage indicates this flaw sits alongside other ALE issues that reportedly allow attackers to gain root access. The CVSS 3.1 base score is 5.3 (medium), reflecting low confidentiality impact only. As of now, the CVE is not in CISA's KEV catalog, no public proof of concept is known, and there are no reports of in-the-wild exploitation.
What to do: Apply the patched ALE release identified in HPE's security advisory for this CVE, since the exact fixed version is not stated in the available data. Restrict ALE management and API interfaces to trusted management VLANs or VPNs so unauthenticated callers cannot reach the affected endpoint. If an instance was exposed, rotate credentials for accounts whose hashes could have been disclosed and audit for follow-on compromise, given related reporting of ALE flaws enabling root access.
Affected
| HPE (HPE Aruba Networking) Analytics and Location Engine (ALE) API | — |
Estimated exposure
moderate≈ Low thousands of enterprise ALE deployments worldwide (estimated), with only a small subset of API interfaces likely internet-exposed — ALE is an optional, on-premises enterprise analytics/virtual-appliance component of HPE Aruba campus networks rather than a mass-market product, and public internet scans typically show only a small number of exposed instances; no…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input to a specific API endpoint. Successful exploitation could result in the disclosure of sensitive user information, including password hashes, which could be used to facilitate further attacks.