---
id: CVE-2026-76724
title: >-
  A command injection vulnerability exists in CLI of the affected HPE Networking
  Instant ON APs that could allow an unauthenticated adjacent attacker to
  perform command injection by sending specially crafted packets
summary: >-
  A command injection vulnerability exists in CLI of the affected HPE Networking
  Instant ON APs that could allow an unauthenticated adjacent attacker to
  perform command injection by sending specially crafted packets. Successful
  exploitatio…
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
vendor: Hewlett Packard Enterprise (HPE)
product: Instant ON
affected:
  - instant_on >= 0.0.0.0 <= 3.4.1.0
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T21:39:02.570'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76724'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T19:44:04.156Z'
---

## Overview

A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
