---
id: CVE-2026-76716
title: >-
  Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that
  may allow for unauthorized access or denial of service
summary: >-
  Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that
  may allow for unauthorized access or denial of service. An unauthenticated
  remote attacker could exploit these vulnerabilities by sending specially
  crafted in…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-770
vendor: Hewlett Packard Enterprise (HPE)
product: ALE
affected:
  - ALE >= 0.0.0.0 <= 5.0.0.0
published: '2026-09-22'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:17:07.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76716'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
epss: 0.00512
epssPercentile: 0.41074
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-22T20:02:12.291280Z'
ingestedAt: '2026-09-22T20:10:15.103Z'
---

## Overview

Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or denial of service. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted input or leveraging improper security configurations. Successful exploitation could result in a denial of service condition or unauthorized access to sensitive information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
