CVE-2026-79811: Hewlett Packard Enterprise HPE Clearpass Policy Manager Cppm

High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.

A SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote authenticated attacker with administrative privileges to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to execute arbitrary database commands.

Affected products

Published 2026-10-06. Last modified 2026-10-08.