CVE-2026-76752
Received
Received - Intake
Authentication Bypass in HPE ClearPass Policy Manager
Vulnerability report for CVE-2026-76752, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: Hewlett Packard Enterprise (HPE)
Description
Description
Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to circumvent existing authentication controls and gain administrative access to the affected system.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Hewlett | Packard | Enterprise (HPE) ClearPass Policy Manager (CPPM) 6.14.0 |
| Hewlett | Packard | Enterprise (HPE) ClearPass Policy Manager (CPPM) 6.11.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |