---
id: CVE-2026-76750
title: >-
  Deserialization of untrusted data vulnerabilities exist in the web interface
  of HPE Networking ClearPass Policy Manager
summary: >-
  Deserialization of untrusted data vulnerabilities exist in the web interface
  of HPE Networking ClearPass Policy Manager. Successful exploitation could
  allow an unauthenticated remote attacker to execute arbitrary code on the
  affected sys…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: Hewlett Packard Enterprise (HPE)
product: ClearPass Policy Manager (CPPM)
affected:
  - clearpass_policy_manager_cppm >= 6.14.0 <= 6.14.0
  - clearpass_policy_manager_cppm >= 6.11.0 <= 6.11.15
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:17:30.397'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76750'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T20:16:42.509Z'
---

## Overview

Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code on the affected system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
