---
id: CVE-2026-76726
title: >-
  An authentication bypass vulnerability in the API endpoint of HPE Networking
  Instant ON could allow an unauthenticated remote attacker to bypass network
  access controls if certain preconditions outside of the attacker's control are
  met
summary: >-
  An authentication bypass vulnerability in the API endpoint of HPE Networking
  Instant ON could allow an unauthenticated remote attacker to bypass network
  access controls if certain preconditions outside of the attacker's control are
  met. …
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: Hewlett Packard Enterprise (HPE)
product: Instant ON
affected:
  - instant_on >= 0.0.0.0 <= 3.4.1.0
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T21:39:02.570'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76726'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T19:44:04.155Z'
---

## Overview

An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to obtain unauthorized access to restricted networks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
