---
id: CVE-2026-76717
title: >-
  A vulnerability exists in the Analytics and Location Engine (ALE) API that may
  allow for the disclosure of sensitive information
summary: >-
  A vulnerability exists in the Analytics and Location Engine (ALE) API that may
  allow for the disclosure of sensitive information. An unauthenticated remote
  attacker could exploit this vulnerability by providing specially crafted input
  to…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: Hewlett Packard Enterprise (HPE)
product: ALE
affected:
  - ALE >= 0.0.0.0 <= 5.0.0.0
published: '2026-09-22'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:17:07.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76717'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
epss: 0.0042
epssPercentile: 0.33559
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-22T20:01:28.413694Z'
ingestedAt: '2026-09-22T20:10:15.094Z'
---

## Overview

A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input to a specific API endpoint. Successful exploitation could result in the disclosure of sensitive user information, including password hashes, which could be used to facilitate further attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
