---
id: CVE-2026-76754
title: >-
  A vulnerability in an affected interface of ClearPass Policy Manager could
  allow an unauthenticated remote attacker to conduct SQL injection attacks
  against the ClearPass Policy Manager instance
summary: >-
  A vulnerability in an affected interface of ClearPass Policy Manager could
  allow an unauthenticated remote attacker to conduct SQL injection attacks
  against the ClearPass Policy Manager instance. Successful exploitation could
  allow an at…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: Hewlett Packard Enterprise (HPE)
product: ClearPass Policy Manager (CPPM)
affected:
  - clearpass_policy_manager_cppm >= 6.14.0 <= 6.14.0
  - clearpass_policy_manager_cppm >= 6.11.0 <= 6.11.15
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:17:30.853'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76754'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T20:16:42.508Z'
---

## Overview

A vulnerability in an affected interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
