{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-79818", "assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0", "state": "PUBLISHED", "assignerShortName": "hpe", "dateReserved": "2026-08-25T14:46:40.580Z", "datePublished": "2026-10-06T19:17:19.720Z", "dateUpdated": "2026-10-07T17:57:48.208Z" }, "containers": { "cna": { "affected": [ { "defaultStatus": "affected", "product": "ClearPass Policy Manager (CPPM)", "vendor": "Hewlett Packard Enterprise (HPE)", "versions": [ { "lessThanOrEqual": "6.14.0", "status": "affected", "version": "6.14.0", "versionType": "semver" }, { "lessThanOrEqual": "6.11.15", "status": "affected", "version": "6.11.0", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "reporter", "value": "Internal security research (HPE Networking)." } ], "descriptions": [ { "lang": "en", "value": "A vulnerability in an API interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to obtain sensitive information from the affected system." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "availabilityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "providerMetadata": { "orgId": "eb103674-0d28-4225-80f8-39fb86215de0", "shortName": "hpe", "dateUpdated": "2026-10-06T19:17:19.720Z" }, "references": [ { "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US" } ], "source": { "advisory": "HPESBNW05158", "discovery": "INTERNAL" }, "title": "Authentication Bypass in the API Interface Allows Unauthorized Information Disclosure in ClearPass Policy Manager", "x_generator": { "engine": "Vulnogram 0.2.0" } }, "adp": [ { "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-306", "lang": "en", "description": "CWE-306 Missing Authentication for Critical Function" } ] } ], "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-07T17:57:25.930763Z", "id": "CVE-2026-79818", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-07T17:57:48.208Z" } } ] } }