---
id: CVE-2026-79796
title: >-
  Vulnerabilities have been identified in the affected interface of ClearPass
  Policy Manager that could potentially allow an unauthenticated remote attacker
  to circumvent existing authentication controls
summary: >-
  Vulnerabilities have been identified in the affected interface of ClearPass
  Policy Manager that could potentially allow an unauthenticated remote attacker
  to circumvent existing authentication controls. Successful exploitation could
  allo…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: Hewlett Packard Enterprise (HPE)
product: ClearPass Policy Manager (CPPM)
affected:
  - clearpass_policy_manager_cppm >= 6.14.0 <= 6.14.0
  - clearpass_policy_manager_cppm >= 6.11.0 <= 6.11.15
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:17:31.083'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79796'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T20:16:42.507Z'
---

## Overview

Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain unauthorized access to the affected system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
