---
id: CVE-2026-76713
title: >-
  A vulnerability exists in the maintenance restore functionality of Analytics
  and Location Engine (ALE)
summary: >-
  A vulnerability exists in the maintenance restore functionality of Analytics
  and Location Engine (ALE). Successful exploitation of this vulnerability could
  allow an authenticated remote attacker to gain unauthorized access to the file
  sy…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
vendor: Hewlett Packard Enterprise (HPE)
product: ALE
affected:
  - ALE >= 0.0.0.0 <= 5.0.0.0
published: '2026-09-22'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:17:07.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76713'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
epss: 0.00551
epssPercentile: 0.43803
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-22T20:05:24.785910Z'
ingestedAt: '2026-09-22T20:10:15.104Z'
---

## Overview

A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file system with root privileges, potentially resulting in full system compromise.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
