CVE-2026-79803

Summary

A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploitation could allow an authenticated remote attacker to escalate privileges and gain administrative control of the affected system.

Affected Software

VendorProductVersion RangeStatus
Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)6.14.0 <= 6.14.0affected
Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)6.11.0 <= 6.11.15affected

Weaknesses

References