{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-76754", "assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0", "state": "PUBLISHED", "assignerShortName": "hpe", "dateReserved": "2026-08-19T16:14:02.299Z", "datePublished": "2026-10-06T19:16:58.629Z", "dateUpdated": "2026-10-07T18:51:53.134Z" }, "containers": { "cna": { "affected": [ { "defaultStatus": "affected", "product": "ClearPass Policy Manager (CPPM)", "vendor": "Hewlett Packard Enterprise (HPE)", "versions": [ { "lessThanOrEqual": "6.14.0", "status": "affected", "version": "6.14.0", "versionType": "semver" }, { "lessThanOrEqual": "6.11.15", "status": "affected", "version": "6.11.0", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "reporter", "value": "Internal security research (HPE Networking)." } ], "descriptions": [ { "lang": "en", "value": "A vulnerability in an affected interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "availabilityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "providerMetadata": { "orgId": "eb103674-0d28-4225-80f8-39fb86215de0", "shortName": "hpe", "dateUpdated": "2026-10-06T19:16:58.629Z" }, "references": [ { "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US" } ], "source": { "advisory": "HPESBNW05158", "discovery": "INTERNAL" }, "title": "Unauthenticated SQL Injection Vulnerability leads to Remote Code Execution in ClearPass Policy Manager", "x_generator": { "engine": "Vulnogram 0.2.0" } }, "adp": [ { "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-77", "lang": "en", "description": "CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')" } ] } ], "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-07T18:51:31.114519Z", "id": "CVE-2026-76754", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-07T18:51:53.134Z" } } ] } }