---
id: CVE-2026-79801
title: >-
  A missing integrity verification vulnerability in the client agent software of
  HPE Networking ClearPass Policy Manager could allow an unauthenticated remote
  attacker to introduce untrusted code
summary: >-
  A missing integrity verification vulnerability in the client agent software of
  HPE Networking ClearPass Policy Manager could allow an unauthenticated remote
  attacker to introduce untrusted code. Successful exploitation could allow an
  att…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: Hewlett Packard Enterprise (HPE)
product: ClearPass Policy Manager (CPPM)
affected:
  - clearpass_policy_manager_cppm >= 6.14.0 <= 6.14.0
  - clearpass_policy_manager_cppm >= 6.11.0 <= 6.11.15
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:17:31.667'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79801'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T20:16:42.505Z'
---

## Overview

A missing integrity verification vulnerability in the client agent software of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to introduce untrusted code. Successful exploitation could allow an attacker to execute arbitrary code on the affected client system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
