{"id":"CVE-2026-23600","title":"A remote authentication bypass vulnerability \n\n exists in HPE AutoPass License Server (APLS).","summary":"A remote authentication bypass vulnerability \n\n exists in HPE AutoPass License Server (APLS).","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-287"],"vendor":"hpe","product":"autopass_license_server","affected":["autopass_license_server < 9.19"],"patched":["autopass_license_server 9.19"],"published":"2026-03-02","updated":"2026-08-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-23600","references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn05003en_us&docLocale=en_US","label":"security-alert@hpe.com"}],"tags":["nvd"],"epss":0.0096,"epssPercentile":0.60016,"ingestedAt":"2026-08-11T16:47:03.975Z","slug":"CVE-2026-23600","body":"## Overview\n\nA remote authentication bypass vulnerability \n\n exists in HPE AutoPass License Server (APLS).\n\n## Affected\n\n- `autopass_license_server < 9.19`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `autopass_license_server 9.19`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}