CVE-2026-79809

Summary

An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability allows an unauthenticated remote attacker to influence authorization decisions and be assigned an unintended role.

Affected Software

VendorProductVersion RangeStatus
Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)6.14.0 <= 6.14.0affected
Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)6.11.0 <= 6.11.15affected

Weaknesses

References