{"id":"CVE-2026-79802","title":"A command injection vulnerability exists in the client software of ClearPass Policy Manager","summary":"A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted input to the affected software to execute arbitrary commands with …","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","vendor":"Hewlett Packard Enterprise (HPE)","product":"ClearPass Policy Manager (CPPM)","affected":["clearpass_policy_manager_cppm >= 6.14.0 <= 6.14.0","clearpass_policy_manager_cppm >= 6.11.0 <= 6.11.15"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T20:17:31.783","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79802","references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US","label":"security-alert@hpe.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T20:16:42.506Z","slug":"CVE-2026-79802","body":"## Overview\n\nA command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted input to the affected software to execute arbitrary commands with elevated privileges on the affected host.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}