---
id: CVE-2026-76709
title: >-
  A vulnerability exists in the internal administrative component of Analytics
  and Location Engine (ALE)
summary: >-
  A vulnerability exists in the internal administrative component of Analytics
  and Location Engine (ALE). Successful exploitation of this vulnerability could
  allow an unauthenticated remote attacker to gain unauthorized write access to
  the…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-284
vendor: Hewlett Packard Enterprise (HPE)
product: ALE
affected:
  - ALE >= 0.0.0.0 <= 5.0.0.0
published: '2026-09-22'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T20:17:14.920'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76709'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-23T12:05:22.333739Z'
epss: 0.0065
epssPercentile: 0.4979
ingestedAt: '2026-09-22T20:10:15.109Z'
---

## Overview

A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain unauthorized write access to the file system with elevated privileges, potentially resulting in full system compromise.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
