---
id: CVE-2026-79797
title: >-
  An improper access control vulnerability exists in the Android client
  application for HPE Networking ClearPass Policy Manager, where application
  functionality may be invoked by untrusted sources
summary: >-
  An improper access control vulnerability exists in the Android client
  application for HPE Networking ClearPass Policy Manager, where application
  functionality may be invoked by untrusted sources. Successful exploitation
  could allow an un…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
vendor: Hewlett Packard Enterprise (HPE)
product: ClearPass Policy Manager (CPPM)
affected:
  - clearpass_policy_manager_cppm >= 6.14.0 <= 6.14.0
  - clearpass_policy_manager_cppm >= 6.11.0 <= 6.11.15
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:17:31.197'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79797'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T20:16:42.507Z'
---

## Overview

An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthenticated remote attacker, with user interaction, to obtain sensitive information from the affected user.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
