CVE-2026-79798Critical· 9.9▾ MidnightSQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Su…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-79800High· 8.8An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager
CVE-2026-76750Critical· 9.8Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager
CVE-2026-76751Critical· 9.8A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager
CVE-2026-76752Critical· 9.8Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager
CVE-2026-76753Critical· 9.8A format string vulnerability in an affected service interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to corrupt process memory
CVE-2026-76754Critical· 9.8A vulnerability in an affected interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance