CVE-2026-79799

Summary

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

Affected Software

VendorProductVersion RangeStatus
Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)6.14.0 <= 6.14.0affected
Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)6.11.0 <= 6.11.15affected

Weaknesses

References