---
id: CVE-2026-79817
title: >-
  A sensitive information disclosure vulnerability exists in the client software
  of HPE Networking ClearPass Policy Manager
summary: >-
  A sensitive information disclosure vulnerability exists in the client software
  of HPE Networking ClearPass Policy Manager. Successful exploitation could
  allow an attacker with local access to the affected system to obtain sensitive
  infor…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
vendor: Hewlett Packard Enterprise (HPE)
product: ClearPass Policy Manager (CPPM)
affected:
  - clearpass_policy_manager_cppm >= 6.14.0 <= 6.14.0
  - clearpass_policy_manager_cppm >= 6.11.0 <= 6.11.15
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:17:33.430'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79817'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T20:16:42.501Z'
---

## Overview

A sensitive information disclosure vulnerability exists in the client software of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an attacker with local access to the affected system to obtain sensitive information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
