CVE-2026-79818
Received
Received - Intake
Authentication Bypass in ClearPass Policy Manager
Vulnerability report for CVE-2026-79818, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: Hewlett Packard Enterprise (HPE)
Description
Description
A vulnerability in an API interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to obtain sensitive information from the affected system.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Hewlett | Packard | Enterprise (HPE) ClearPass Policy Manager (CPPM) 6.14.0 |
| Hewlett | Packard | Enterprise (HPE) ClearPass Policy Manager (CPPM) 6.11.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |