---
id: CVE-2026-79818
title: >-
  A vulnerability in an API interface of ClearPass Policy Manager could allow an
  unauthenticated remote attacker to circumvent existing authentication controls
summary: >-
  A vulnerability in an API interface of ClearPass Policy Manager could allow an
  unauthenticated remote attacker to circumvent existing authentication
  controls. Successful exploitation could allow an attacker to obtain sensitive
  informatio…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
vendor: Hewlett Packard Enterprise (HPE)
product: ClearPass Policy Manager (CPPM)
affected:
  - clearpass_policy_manager_cppm >= 6.14.0 <= 6.14.0
  - clearpass_policy_manager_cppm >= 6.11.0 <= 6.11.15
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:17:33.550'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79818'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T20:16:42.500Z'
---

## Overview

A vulnerability in an API interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to obtain sensitive information from the affected system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
