{"id":"CVE-2026-76754","title":"A vulnerability in an affected interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance","summary":"A vulnerability in an affected interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an at…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"Hewlett Packard Enterprise (HPE)","product":"ClearPass Policy Manager (CPPM)","affected":["clearpass_policy_manager_cppm >= 6.14.0 <= 6.14.0","clearpass_policy_manager_cppm >= 6.11.0 <= 6.11.15"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T20:17:30.853","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76754","references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US","label":"security-alert@hpe.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T20:16:42.508Z","slug":"CVE-2026-76754","body":"## Overview\n\nA vulnerability in an affected interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}