CVE-2026-73789: Hewlett Packard Enterprise HPE Clearpass Policy Manager Cppm
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability in the web-based management interface of CPPM guest account management services could allow an unauthenticated remote attacker to manipulate account settings. Successful exploitation could allow an attacker to extend network access beyond policy limits, leading to unauthorized prolonged use of network resources.
Affected products
- Hewlett Packard Enterprise HPE Clearpass Policy Manager Cppm: from 6.12.0, up to and including 6.12.8; from 6.11.0, up to and including 6.11.14
Published 2026-09-09. Last modified 2026-09-10.