CVE-2025-27086: HPE Performance Cluster Manager

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.

Affected products

  • HPE Performance Cluster Manager: before 1.13 (fixed in 1.13)

Published 2025-04-21. Last modified 2026-06-17.