CVE-2026-79798

Summary

SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.

Affected Software

VendorProductVersion RangeStatus
Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)6.14.0 <= 6.14.0affected
Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)6.11.0 <= 6.11.15affected

Weaknesses

References