CVE-2026-79794: Hewlett Packard Enterprise HPE Clearpass Policy Manager Cppm

Critical severity, CVSS 9.1. EPSS: 0.3% chance of exploitation in the next 30 days.

A SQL injection vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.

Affected products

Published 2026-10-06. Last modified 2026-10-08.