cbcvebase.
CVE-2026-73789
published 2026-09-09

CVE-2026-73789: A vulnerability in the web-based management interface of CPPM guest account management services could allow an unauthenticated remote attacker to manipulate…

PriorityP433medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.30%
22.6th percentile
A vulnerability in the web-based management interface of CPPM guest account management services could allow an unauthenticated remote attacker to manipulate account settings. Successful exploitation could allow an attacker to extend network access beyond policy limits, leading to unauthorized prolonged use of network resources.

Affected

2 ranges
VendorProductVersion rangeFixed in
hewlett_packard_enterpriseclearpass_policy_manager6.11.0 – 6.11.14—
hewlett_packard_enterpriseclearpass_policy_manager6.12.0 – 6.12.8—
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.