CVE-2026-79815
Received
Received - Intake
Command Injection in ClearPass Policy Manager OnGuard Agent
Vulnerability report for CVE-2026-79815, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: Hewlett Packard Enterprise (HPE)
Description
Description
A command injection vulnerability in the OnGuard agent of ClearPass Policy Manager could allow an authenticated remote attacker to inject arbitrary commands. Successful exploitation could allow an attacker to execute commands with elevated privileges on the affected Windows endpoint.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Hewlett | Packard | Enterprise (HPE) ClearPass Policy Manager (CPPM) 6.14.0 |
| Hewlett | Packard | Enterprise (HPE) ClearPass Policy Manager (CPPM) 6.11.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |