CVE-2026-76754: Hewlett Packard Enterprise HPE Clearpass Policy Manager Cppm
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability in an affected interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.
Affected products
- Hewlett Packard Enterprise HPE Clearpass Policy Manager Cppm: from 6.14.0, up to and including 6.14.0; from 6.11.0, up to and including 6.11.15
Published 2026-10-06. Last modified 2026-10-08.