{"id":"CVE-2026-76713","title":"A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE)","summary":"A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file sy…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-269"],"vendor":"Hewlett Packard Enterprise (HPE)","product":"ALE","affected":["ALE >= 0.0.0.0 <= 5.0.0.0"],"published":"2026-09-22","updated":"2026-09-23","sourceUpdated":"2026-09-23T18:17:07.270","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76713","references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US","label":"security-alert@hpe.com"}],"tags":["nvd","cve.org"],"epss":0.00551,"epssPercentile":0.44953,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-22T20:05:24.785910Z"},"ingestedAt":"2026-09-22T20:10:15.104Z","slug":"CVE-2026-76713","body":"## Overview\n\nA vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file system with root privileges, potentially resulting in full system compromise.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}