T

Threats

HPE ClearPass Policy Manager Critical Vulnerabilities

Overview

HPE has released patches addressing ten Critical vulnerabilities highlighted in this advisory for ClearPass Policy Manager and its OnGuard and client-agent software. The flaws could allow code execution, authentication bypass, arbitrary database commands and unauthorised file access or modification. Several require no authentication, while the SQL injection flaws include low- and high-privileged attack paths.

This report covers the ten Critical CVEs supplied for this project. HPE bulletin HPESBNW05158 also covers additional High and Medium vulnerabilities outside this report’s technical breakdown. HPE’s fixes should be applied for the full bulletin, not only the ten CVEs highlighted here.

Affected Versions

HPE’s CSAF advisory maps all ten CVEs in this report to the same CPPM release ranges and fixes. The bulletin describes the affected releases as CPPM 6.14.0 and below, and CPPM 6.11.15 and below; the entries below give the explicit supported-branch ranges in CSAF.

ClearPass Policy Manager - 6.14 branch

ClearPass Policy Manager - 6.11 branch

OnGuard and client-agent software

The OnGuard flaw, CVE-2026-76751, and client-agent flaw, CVE-2026-79801, use the same CPPM version mapping above in HPE’s CSAF advisory. For standalone OnGuard and client-agent builds, The vendor has not specified an exact affected-version range as of 6 October 2026. The CPPM release ranges above are specified in the HPE CSAF advisory. HPE does not give platform-specific unaffected configurations for these two CVEs. Do not interpret the CPPM release numbers as independently verified endpoint-agent build numbers. Use the HPE bulletin to coordinate server and client remediation.

Lifecycle caveat: HPE presumes end-of-maintenance releases are affected unless explicitly stated otherwise. Exposure on end-of-support releases has not been assessed and should be considered potentially impacted. Upgrade unsupported deployments to a supported release, as directed in the HPE bulletin.


Vulnerability Breakdown

CVE-2026-79798 - Authenticated SQL injection

  • Severity: Critical

  • CVSS v3.1: 9.9

  • Description: SQL injection flaws affect the web-based management interface. A low-privileged authenticated remote attacker could run arbitrary database commands.

  • Impact: Arbitrary database commands, risking database confidentiality, integrity and availability.

  • Conditions: Low-privileged authenticated remote access. No user interaction is required by the published CVSS vector.

  • Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.

  • Source: HPE security bulletin HPESBNW05158, rev.1

CVE-2026-76750 - Untrusted deserialisation and remote code execution

  • Severity: Critical

  • CVSS v3.1: 9.8

  • Description: The web interface deserialises untrusted data. An unauthenticated remote attacker could execute arbitrary code on the affected system.

  • Impact: Arbitrary code execution on the ClearPass system.

  • Conditions: Unauthenticated remote access to the affected web interface.

  • Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.

  • Source: HPE security bulletin HPESBNW05158, rev.1

CVE-2026-76751 - OnGuard integrity verification failure

  • Severity: Critical

  • CVSS v3.1: 9.8

  • Description: Missing integrity verification affects the OnGuard agent. An unauthenticated remote attacker could execute arbitrary code on an affected endpoint.

  • Impact: Endpoint code execution with the elevated privileges of the agent.

  • Conditions: Unauthenticated remote attack against an affected OnGuard agent.

  • Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.

  • Source: HPE security bulletin HPESBNW05158, rev.1

CVE-2026-76752 - Management and API authentication bypass

  • Severity: Critical

  • CVSS v3.1: 9.8

  • Description: Authentication bypass flaws affect the web-based management and API interfaces. An unauthenticated remote attacker could circumvent authentication controls.

  • Impact: Unauthorised administrative access to the affected system.

  • Conditions: Unauthenticated remote access to an affected management or API interface.

  • Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.

  • Source: HPE security bulletin HPESBNW05158, rev.1

CVE-2026-76753 - Format string flaw and remote code execution

  • Severity: Critical

  • CVSS v3.1: 9.8

  • Description: A format string flaw in an affected service interface could allow an unauthenticated remote attacker to corrupt process memory. Successful exploitation could allow arbitrary code execution.

  • Impact: Process memory corruption and potential arbitrary code execution.

  • Conditions: Unauthenticated remote access to the affected service interface.

  • Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.

  • Source: HPE security bulletin HPESBNW05158, rev.1

CVE-2026-76754 - Unauthenticated SQL injection

  • Severity: Critical

  • CVSS v3.1: 9.8

  • Description: SQL injection affects an interface of ClearPass Policy Manager. An unauthenticated remote attacker could run arbitrary database commands.

  • Impact: Arbitrary database commands. HPE titles this flaw as leading to remote code execution.

  • Conditions: Unauthenticated remote access to the affected interface.

  • Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.

  • Source: HPE security bulletin HPESBNW05158, rev.1

CVE-2026-79796 - Authentication bypass

  • Severity: Critical

  • CVSS v3.1: 9.8

  • Description: Flaws in an affected ClearPass interface could allow an unauthenticated remote attacker to circumvent authentication controls.

  • Impact: Unauthorised access to the affected system.

  • Conditions: Unauthenticated remote access to the affected interface.

  • Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.

  • Source: HPE security bulletin HPESBNW05158, rev.1

CVE-2026-79801 - Client-agent integrity verification failure

  • Severity: Critical

  • CVSS v3.1: 9.8

  • Description: Missing integrity verification in the client-agent software could allow an unauthenticated remote attacker to introduce untrusted code.

  • Impact: Arbitrary code execution on an affected client system.

  • Conditions: Unauthenticated remote attack against the affected client-agent software.

  • Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.

  • Source: HPE security bulletin HPESBNW05158, rev.1

CVE-2026-79805 - Path traversal and unauthorised file access

  • Severity: Critical

  • CVSS v3.1: 9.8

  • Description: HPE describes an authenticated path traversal flaw in ClearPass Policy Manager. Successful exploitation could allow an attacker to read and modify certain files on the underlying operating system.

  • Impact: Unauthorised access to and modification of certain operating system files.

  • Conditions: HPE describes authenticated exploitation, but its published CVSS vector lists PR:N, meaning no privileges required. HPE does not reconcile this inconsistency. The score is reproduced as published; no privilege level is inferred.

  • Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.

  • Source: HPE security bulletin HPESBNW05158, rev.1

CVE-2026-79794 - High-privileged SQL injection

  • Severity: Critical

  • CVSS v3.1: 9.1

  • Description: SQL injection affects the web-based management interface. An authenticated remote attacker could run arbitrary database commands.

  • Impact: Arbitrary database commands, risking database confidentiality, integrity and availability.

  • Conditions: Authenticated remote access. HPE’s CVSS vector specifies high privileges and no user interaction.

  • Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.

  • Source: HPE security bulletin HPESBNW05158, rev.1


Mitigation

  • Upgrade immediately: Move affected deployments to CPPM 6.14.1 or later in the 6.14 branch, or 6.11.16 or later in the 6.11 branch, as applicable. Obtain the vendor software from the HPE Networking Support Portal, following the security bulletin resolution.

  • Account for endpoint exposure: Include OnGuard and client-agent software in remediation planning. HPE identifies endpoint code-execution risks as well as server-side flaws in the bulletin. Confirm the appropriate client packages and deployment procedure with HPE; do not assume patching a server automatically updates installed agents.

  • Restrict management access while remediation proceeds: HPE recommends a dedicated layer 2 segment/VLAN and/or layer 3 and above firewall policies for CLI and web-based management interfaces. Apply accounting controls to track and log user activities and resource usage. This is HPE’s risk-reduction workaround, not a replacement for the required software updates.

  • Review upgrade and hardening guidance: Consult the 6.14.1 release notes or 6.11.16 release notes and the relevant 6.14 Hardening Guide or 6.11 Hardening Guide.


Summary for IT Teams

  • Products: HPE ClearPass Policy Manager, affected OnGuard and client-agent software.

  • Threat Level: Critical, CVSS v3.1 9.1 to 9.9 for the ten highlighted CVEs.

  • Action Required: Prioritise the applicable 6.14.1 or 6.11.16 update, confirm endpoint-agent remediation, restrict management interfaces and retain activity logs. Refer to the HPE remediation guidance.


Reference


Need Help?

Please get in touch on 1300 769 460 or email the Secure ISS SOC team. We are here to help you strengthen your cybersecurity posture.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.