TL;DR
HPE Networking has fixed 28 ClearPass Policy Manager vulnerabilities in a single advisory, and ten of them rate Critical. The worst flaws let an unauthenticated remote attacker run code or gain admin access. Admins should upgrade to CPPM 6.14.1 or 6.11.16.
- Total: 28 CVEs
- Severity: 10 Critical · 11 High · 7 Medium
- Actively exploited: None confirmed
- Highest severity: 9.9 (Critical · CVSSv3) — CVE-2026-79798
- Action: Apply the latest security updates now
Route critical CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-79798 | 9.9 | Authenticated SQL Injection in ClearPass Policy Manager Web-Based Management Interface | Not exploited |
| CVE-2026-76750 | 9.8 | Unauthenticated Deserialization of Untrusted Data allows Remote Code Execution in the Web Interface of HPE Networking ClearPass Policy Manager | Not exploited |
| CVE-2026-76751 | 9.8 | Missing Integrity Verification in the OnGuard Agent of ClearPass Policy Manager Allows Unauthenticated Remote Code Execution | Not exploited |
| CVE-2026-76752 | 9.8 | Authentication Bypass in HPE Networking ClearPass Policy Manager Allow Unauthorized Administrative Access | Not exploited |
| CVE-2026-76753 | 9.8 | Unauthenticated Format String in HPE Networking ClearPass Policy Manager | Not exploited |
| CVE-2026-76754 | 9.8 | Unauthenticated SQL Injection leads to Remote Code Execution in ClearPass Policy Manager | Not exploited |
| CVE-2026-79796 | 9.8 | Authentication Bypass in ClearPass Policy Manager | Not exploited |
| CVE-2026-79801 | 9.8 | Unauthenticated Missing Integrity Verification allows Remote Code Execution in ClearPass Policy Manager Client Agent | Not exploited |
Why It Matters
ClearPass Policy Manager (CPPM) is HPE’s network access control platform. It decides which users and devices can join a corporate network. As a result, an attacker who controls CPPM can shape who gets in and what they reach.
The bugs span the server, its web and API interfaces, and the OnGuard agents that run on endpoints. According to the CVSS vectors, 15 of the flaws need no login and work over the network. HPE itself urges action. “Customers are strongly urged to patch their instances due to the complexity, breadth, and impact of these vulnerabilities,” the bulletin says.
So far, there is no sign of attacks. HPE says it “is not aware of any public discussion or exploit code that targets the listed vulnerabilities as of the release date of this advisory.” Its own internal security research found most of the bugs.
How the Attacks Work
Unauthenticated Server Flaws
Several of the ClearPass Policy Manager vulnerabilities score 9.8. CVE-2026-76750 is a deserialization bug in the web interface. Per HPE, it “could allow an unauthenticated remote attacker to execute arbitrary code on the affected system.” Next, CVE-2026-76752 lets an attacker “circumvent existing authentication controls and gain administrative access.” In addition, CVE-2026-76753 is a format string bug that can corrupt memory and run code. CVE-2026-76754 opens the door to unauthenticated SQL injection.
Agent and Client Flaws
The OnGuard and client agents carry their own risks. CVE-2026-76751 and CVE-2026-79801 are missing integrity checks. They could let a remote attacker push untrusted code to endpoints. Meanwhile, several local bugs allow privilege escalation on Windows and Linux agents.
Authenticated Flaws
The top score, 9.9, goes to CVE-2026-79798. This SQL injection bug needs only a low-privileged account. It “could allow an attacker to run arbitrary database commands.” Other logged-in attacks include path traversal, command injection and stored cross-site scripting.
Affected Versions
The bulletin lists these releases as affected:
- CPPM 6.14.0 and below
- CPPM 6.11.15 and below
One exception applies. CVE-2026-79800 is fixed only in 6.14.1, and HPE says it “is not applicable to the 6.11.x branch.” Also note that HPE presumes end-of-maintenance releases are affected, though it does not cover them.
Patch and Mitigation Steps
First, upgrade to CPPM 6.14.1 or later, or 6.11.16 or later. The fixed builds are available from the HPE Networking Support Portal.
If you cannot patch at once, limit access to management interfaces. HPE recommends placing the CLI and web interfaces on “a dedicated layer 2 segment/VLAN” or behind firewall policies. It also advises logging user activity. Given the number of ClearPass Policy Manager vulnerabilities, treat this update as urgent, even without confirmed attacks.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!