cbcvebase.

Hewlett Packard Enterprise Clearpass Policy Manager vulnerabilities

36 known vulnerabilities affecting hewlett_packard_enterprise/clearpass_policy_manager.

Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH15MEDIUM11

Vulnerabilities

Page 1 of 2
CVE-2026-76752P2CRITICALCVSS 9.8≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-76752 [CRITICAL] CVE-2026-76752: Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Ne Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to circumvent existing authentication controls and gain administrative access to the affected system.
nvd
CVE-2026-76751P2CRITICALCVSS 9.8≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-76751 [CRITICAL] CVE-2026-76751: A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manag A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an unauthenticated, remote attacker to execute arbitrary code on the affected endpoint with the elevated privileges of the agent.
nvd
CVE-2026-76750P2CRITICALCVSS 9.8≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-76750 [CRITICAL] CVE-2026-76750: Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking Clear Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code on the affected system.
nvd
CVE-2026-79796P2CRITICALCVSS 9.8≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79796 [CRITICAL] CVE-2026-79796: Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that coul Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain unauthorized access to the affected system.
nvd
CVE-2026-76754P2CRITICALCVSS 9.8≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-76754 [CRITICAL] CVE-2026-76754: A vulnerability in an affected interface of ClearPass Policy Manager could allow an unauthenticated A vulnerability in an affected interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.
nvd
CVE-2026-79801P2CRITICALCVSS 9.8≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79801 [CRITICAL] CVE-2026-79801: A missing integrity verification vulnerability in the client agent software of HPE Networking ClearP A missing integrity verification vulnerability in the client agent software of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to introduce untrusted code. Successful exploitation could allow an attacker to execute arbitrary code on the affected client system.
nvd
CVE-2026-79798P2CRITICALCVSS 9.9≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79798 [CRITICAL] CVE-2026-79798: SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager coul SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.
nvd
CVE-2026-76753P2CRITICALCVSS 9.8≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-76753 [CRITICAL] CVE-2026-76753: A format string vulnerability in an affected service interface of HPE Networking ClearPass Policy Ma A format string vulnerability in an affected service interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to corrupt process memory. Successful exploitation could allow an attacker to execute arbitrary code.
nvd
CVE-2026-79800P3HIGHCVSS 8.8≥ 6.14.0, ≤ 6.14.02026-10-06
CVE-2026-79800 [HIGH] CVE-2026-79800: An authenticated path traversal vulnerability exists in the command line interface of ClearPass Poli An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager. Successful exploitation could allow a low-privileged authenticated remote attacker to execute arbitrary code with elevated privileges on the underlying operating system.
nvd
CVE-2026-79803P3HIGHCVSS 8.8≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79803 [HIGH] CVE-2026-79803: A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploita A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploitation could allow an authenticated remote attacker to escalate privileges and gain administrative control of the affected system.
nvd
CVE-2026-79802P3HIGHCVSS 8.8≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79802 [HIGH] CVE-2026-79802: A command injection vulnerability exists in the client software of ClearPass Policy Manager. Success A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted input to the affected software to execute arbitrary commands with elevated privileges on the affected host.
nvd
CVE-2026-73769P3HIGHCVSS 7.2≥ 6.12.0, ≤ 6.12.8≥ 6.11.0, ≤ 6.11.142026-09-09
CVE-2026-73769 [HIGH] CWE-78 CVE-2026-73769: A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an auth A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
nvd
CVE-2024-41915P3HIGHCVSS 8.8≥ ClearPass Policy Manager 6.12.1 and below, ≤ <=6.12.1≥ ClearPass Policy Manager 6.11.8 and below, ≤ <=6.11.82024-07-30
CVE-2024-41915 [HIGH] CWE-89 CVE-2024-41915: A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an aut A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying database potentially leading to complete
nvd
CVE-2026-79805P3CRITICALCVSS 9.8≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79805 [CRITICAL] CVE-2026-79805: An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploit An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an attacker to read and modify certain files on the underlying operating system.
nvd
CVE-2026-79794P3CRITICALCVSS 9.1≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79794 [CRITICAL] CVE-2026-79794: A SQL injection vulnerability in the web-based management interface of ClearPass Policy Manager coul A SQL injection vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.
nvd
CVE-2026-73787P3HIGHCVSS 7.2≥ 6.11.0, ≤ 6.11.142026-09-09
CVE-2026-73787 [HIGH] CWE-78 CVE-2026-73787: A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access dir A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information on a vulnerable system. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
nvd
CVE-2026-79810P3HIGHCVSS 7.2≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79810 [HIGH] CVE-2026-79810: Remote code execution vulnerabilities exist in the affected interface of HPE Networking ClearPass Po Remote code execution vulnerabilities exist in the affected interface of HPE Networking ClearPass Policy Manager that could allow an authenticated remote attacker with high privileges to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
nvd
CVE-2026-79799P3HIGHCVSS 8.8≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79799 [HIGH] CVE-2026-79799: A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an una A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affecte
nvd
CVE-2026-79809P3HIGHCVSS 7.3≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79809 [HIGH] CVE-2026-79809: An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manage An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability allows an unauthenticated remote attacker to influence authorization decisions and be assigned an unintended role.
nvd
CVE-2026-79797P3HIGHCVSS 8.8≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79797 [HIGH] CVE-2026-79797: An improper access control vulnerability exists in the Android client application for HPE Networking An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthenticated remote attacker, with user interaction, to obtain sensitive information from the affected user.
nvd
Hewlett Packard Enterprise Clearpass Policy Manager vulnerabilities | cvebase