CVE-2026-79809: Hewlett Packard Enterprise HPE Clearpass Policy Manager Cppm
High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.
An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability allows an unauthenticated remote attacker to influence authorization decisions and be assigned an unintended role.
Affected products
- Hewlett Packard Enterprise HPE Clearpass Policy Manager Cppm: from 6.14.0, up to and including 6.14.0; from 6.11.0, up to and including 6.11.15
Published 2026-10-06. Last modified 2026-10-07.