---
id: CVE-2026-79794
title: >-
  A SQL injection vulnerability in the web-based management interface of
  ClearPass Policy Manager could allow an authenticated remote attacker to
  conduct SQL injection attacks against the ClearPass Policy Manager instance
summary: >-
  A SQL injection vulnerability in the web-based management interface of
  ClearPass Policy Manager could allow an authenticated remote attacker to
  conduct SQL injection attacks against the ClearPass Policy Manager instance.
  Successful explo…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
vendor: Hewlett Packard Enterprise (HPE)
product: ClearPass Policy Manager (CPPM)
affected:
  - clearpass_policy_manager_cppm >= 6.14.0 <= 6.14.0
  - clearpass_policy_manager_cppm >= 6.11.0 <= 6.11.15
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:17:30.967'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79794'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T20:16:42.507Z'
---

## Overview

A SQL injection vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
