HPE Networking Analytics Engine Flaws Let Attackers Gain Root Access
HPE patched ten Analytics Engine flaws, including unauthenticated bugs that can give attackers root.
HPE advisory HPESBNW05137 covers 10 vulnerabilities in Networking Analytics and Location Engine versions 5.0.0.0 and earlier, used with ArubaOS Wi-Fi controllers and gateways. CVE-2026-76708 and CVE-2026-76709, both CVSS 9.8, allow unauthenticated remote access via hard-coded credentials and arbitrary elevated file writes. Authenticated flaws CVE-2026-76713 and CVE-2026-76714 can provide root filesystem access or root command execution. HPE said it knew of no public exploit code and advised restricting CLI and web management access until patches are applied.
68