cbcvebase.
CVE-2026-79809
published 2026-10-06

CVE-2026-79809: An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability allows an…

PriorityP349high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability allows an unauthenticated remote attacker to influence authorization decisions and be assigned an unintended role.

Affected

2 ranges
VendorProductVersion rangeFixed in
hewlett_packard_enterpriseclearpass_policy_manager6.11.0 – 6.11.15—
hewlett_packard_enterpriseclearpass_policy_manager6.14.0 – 6.14.0—
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.