---
id: CVE-2026-73769
title: Authenticated Remote Code Execution in CPPM Web Interface
summary: >-
  A vulnerability in the web-based management interface of vulnerable CPPM
  systems could allow an authenticated remote attacker to achieve remote code
  execution. Successful exploitation could allow an attacker to execute
  arbitrary commands…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
vendor: Hewlett Packard Enterprise (HPE)
product: ClearPass Policy Manager (CPPM)
affected:
  - clearpass_policy_manager_cppm >= 6.12.0 <= 6.12.8
  - clearpass_policy_manager_cppm >= 6.11.0 <= 6.11.14
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-10T00:00:00+00:00'
published: '2026-09-09'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T03:56:32.855Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-73769'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05130en_us&docLocale=en_US
tags:
  - cve.org
epss: 0.01058
epssPercentile: 0.62985
ingestedAt: '2026-09-11T16:45:47.926Z'
---

## Overview

A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

## Affected

- `clearpass_policy_manager_cppm >= 6.12.0 <= 6.12.8`
- `clearpass_policy_manager_cppm >= 6.11.0 <= 6.11.14`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
