---
id: CVE-2026-73789
title: >-
  A vulnerability in the web-based management interface of CPPM guest account
  management services could allow an unauthenticated remote attacker to
  manipulate account settings
summary: >-
  A vulnerability in the web-based management interface of CPPM guest account
  management services could allow an unauthenticated remote attacker to
  manipulate account settings. Successful exploitation could allow an attacker
  to extend netw…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-284
vendor: Hewlett Packard Enterprise (HPE)
product: ClearPass Policy Manager (CPPM)
affected:
  - clearpass_policy_manager_cppm >= 6.12.0 <= 6.12.8
  - clearpass_policy_manager_cppm >= 6.11.0 <= 6.11.14
published: '2026-09-09'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:47:22.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73789'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05130en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-10T13:53:57.154473Z'
ingestedAt: '2026-09-09T21:22:45.592Z'
epss: 0.00402
epssPercentile: 0.31639
---

## Overview

A vulnerability in the web-based management interface of CPPM guest account management services could allow an unauthenticated remote attacker to manipulate account settings. Successful exploitation could allow an attacker to extend network access beyond policy limits, leading to unauthorized prolonged use of network resources.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
