CVE-2026-79797High· 8.8▾ TwilightAn improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an un…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthenticated remote attacker, with user interaction, to obtain sensitive information from the affected user.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-79800High· 8.8An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager
CVE-2026-76750Critical· 9.8Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager
CVE-2026-76751Critical· 9.8A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager
CVE-2026-76752Critical· 9.8Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager
CVE-2026-76753Critical· 9.8A format string vulnerability in an affected service interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to corrupt process memory
CVE-2026-76754Critical· 9.8A vulnerability in an affected interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance