---
id: CVE-2026-76752
title: >-
  Authentication bypass vulnerabilities exist in the web-based management and
  API interfaces of HPE Networking ClearPass Policy Manager
summary: >-
  Authentication bypass vulnerabilities exist in the web-based management and
  API interfaces of HPE Networking ClearPass Policy Manager. Successful
  exploitation could allow an unauthenticated remote attacker to circumvent
  existing authenti…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: Hewlett Packard Enterprise (HPE)
product: ClearPass Policy Manager (CPPM)
affected:
  - clearpass_policy_manager_cppm >= 6.14.0 <= 6.14.0
  - clearpass_policy_manager_cppm >= 6.11.0 <= 6.11.15
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:17:30.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76752'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T20:16:42.509Z'
---

## Overview

Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to circumvent existing authentication controls and gain administrative access to the affected system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
