---
id: CVE-2026-76710
title: >-
  A vulnerability exists in the Analytics and Location Engine (ALE) management
  interface that may allow for the disclosure of sensitive information
summary: >-
  A vulnerability exists in the Analytics and Location Engine (ALE) management
  interface that may allow for the disclosure of sensitive information. An
  unauthenticated remote attacker could exploit this vulnerability by sending
  specially c…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
vendor: Hewlett Packard Enterprise (HPE)
product: ALE
affected:
  - ALE >= 0.0.0.0 <= 5.0.0.0
published: '2026-09-22'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T20:17:15.053'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76710'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-23T12:06:56.198465Z'
epss: 0.00538
epssPercentile: 0.42887
ingestedAt: '2026-09-22T20:10:15.110Z'
---

## Overview

A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted requests to certain internal endpoints. Successful exploitation could result in the disclosure of sensitive site hierarchy, infrastructure details, and client device information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
