{"id":"CVE-2026-76709","title":"A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE)","summary":"A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain unauthorized write access to the…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"Hewlett Packard Enterprise (HPE)","product":"ALE","affected":["ALE >= 0.0.0.0 <= 5.0.0.0"],"published":"2026-09-22","updated":"2026-09-22","sourceUpdated":"2026-09-22T20:17:06.750","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76709","references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US","label":"security-alert@hpe.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-22T20:10:15.109Z","slug":"CVE-2026-76709","body":"## Overview\n\nA vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain unauthorized write access to the file system with elevated privileges, potentially resulting in full system compromise.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}