securityonline.info 7 Oct 2026, 01:44 UTC

HPE Urges Urgent Patching for 28 Critical ClearPass Flaws

HP networking has issued a security bulletin covering 28 vulnerabilities across ClearPass Policy Manager (CPPM), with ten rated as Critical. The flaws span server, web API and OnGuard agent components, and at least 15 can be exploited without authentication over the network. The worst issues could allow an unauthenticated attacker to remotely execute code or gain administrative access, prompting HPE to urge immediate patching. The article notes that there is no public exploitation reported at the time of the advisory, though internal research found the majority of bugs.

Notable CVEs highlighted include CVE-2026-79798, a highly severe authenticated SQL injection that could let an attacker run arbitrary database commands; CVE-2026-76750, an unauthenticated deserialization flaw enabling remote code execution in the web interface; CVE-2026-76752, an authentication bypass; and CVE-2026-76753 and CVE-2026-76754, a format-string bug and an unauthenticated SQL injection respectively.

Additional issues affect OnGuard agent integrity checks (CVE-2026-76751) and client agent integrity (CVE-2026-79801), both of which could allow remote code delivery to endpoints. Several other flaws represent authenticated or mixed-impact risks. The highest severity is CVSSv3 9.9 for CVE-2026-79798.

Affected CPPM versions include 6.14.0 and below and 6.11.15 and below; one exception, CVE-2026-79800, is fixed only in 6.14.1 and not applicable to the 6.11.x branch. Patches are available in CPPM 6.14.1 or later or 6.11.16 or later. If immediate patching isn’t possible, HPE recommends restricting access to management interfaces and monitoring activity. Evidence from the bulletin indicates this should be treated as urgent, even in the absence of confirmed exploitation.

View full article

Article by CyberSIXT