---
id: CVE-2026-79809
title: >-
  An unauthenticated path traversal vulnerability exists in an API endpoint of
  ClearPass Policy Manager
summary: >-
  An unauthenticated path traversal vulnerability exists in an API endpoint of
  ClearPass Policy Manager. Successful exploitation of this vulnerability allows
  an unauthenticated remote attacker to influence authorization decisions and be
  as…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
vendor: Hewlett Packard Enterprise (HPE)
product: ClearPass Policy Manager (CPPM)
affected:
  - clearpass_policy_manager_cppm >= 6.14.0 <= 6.14.0
  - clearpass_policy_manager_cppm >= 6.11.0 <= 6.11.15
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:17:32.483'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79809'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T20:16:42.503Z'
---

## Overview

An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability allows an unauthenticated remote attacker to influence authorization decisions and be assigned an unintended role.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
