T
Threats
HPE ClearPass Policy Manager Critical Vulnerabilities
Overview
Product: HPE Networking ClearPass Policy Manager (CPPM), including affected OnGuard and client-agent software.
CVEs: CVE-2026-79798, CVE-2026-76750, CVE-2026-76751, CVE-2026-76752, CVE-2026-76753, CVE-2026-76754, CVE-2026-79796, CVE-2026-79801, CVE-2026-79805, CVE-2026-79794
Severity: Critical, highest CVSS v3.1 score 9.9.
Advisory date: 6 October 2026.
HPE has released patches addressing ten Critical vulnerabilities highlighted in this advisory for ClearPass Policy Manager and its OnGuard and client-agent software. The flaws could allow code execution, authentication bypass, arbitrary database commands and unauthorised file access or modification. Several require no authentication, while the SQL injection flaws include low- and high-privileged attack paths.
This report covers the ten Critical CVEs supplied for this project. HPE bulletin HPESBNW05158 also covers additional High and Medium vulnerabilities outside this report’s technical breakdown. HPE’s fixes should be applied for the full bulletin, not only the ten CVEs highlighted here.
Affected Versions
HPE’s CSAF advisory maps all ten CVEs in this report to the same CPPM release ranges and fixes. The bulletin describes the affected releases as CPPM 6.14.0 and below, and CPPM 6.11.15 and below; the entries below give the explicit supported-branch ranges in CSAF.
ClearPass Policy Manager - 6.14 branch
Affected: CPPM 6.14.0.
Fixed: CPPM 6.14.1 and later releases in the applicable branch.
Not affected: HPE identifies 6.14.1 as fixed. The bulletin states that other HPE Networking products and software versions not specifically listed are unaffected, subject to its end-of-maintenance and end-of-support caveats below.
Source: HPE HPESBNW05158 CSAF affected and fixed product mapping and HPE security bulletin resolution.
ClearPass Policy Manager - 6.11 branch
Affected: CPPM 6.11.0 to 6.11.15 inclusive.
Fixed: CPPM 6.11.16 and later releases in the applicable branch.
Not affected: HPE identifies 6.11.16 as fixed. The same unaffected-product statement and lifecycle caveats apply.
Source: HPE HPESBNW05158 CSAF affected and fixed product mapping and HPE security bulletin resolution.
OnGuard and client-agent software
The OnGuard flaw, CVE-2026-76751, and client-agent flaw, CVE-2026-79801, use the same CPPM version mapping above in HPE’s CSAF advisory. For standalone OnGuard and client-agent builds, The vendor has not specified an exact affected-version range as of 6 October 2026. The CPPM release ranges above are specified in the HPE CSAF advisory. HPE does not give platform-specific unaffected configurations for these two CVEs. Do not interpret the CPPM release numbers as independently verified endpoint-agent build numbers. Use the HPE bulletin to coordinate server and client remediation.
Lifecycle caveat: HPE presumes end-of-maintenance releases are affected unless explicitly stated otherwise. Exposure on end-of-support releases has not been assessed and should be considered potentially impacted. Upgrade unsupported deployments to a supported release, as directed in the HPE bulletin.
Vulnerability Breakdown
CVE-2026-79798 - Authenticated SQL injection
Severity: Critical
CVSS v3.1: 9.9
Description: SQL injection flaws affect the web-based management interface. A low-privileged authenticated remote attacker could run arbitrary database commands.
Impact: Arbitrary database commands, risking database confidentiality, integrity and availability.
Conditions: Low-privileged authenticated remote access. No user interaction is required by the published CVSS vector.
Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.
CVE-2026-76750 - Untrusted deserialisation and remote code execution
Severity: Critical
CVSS v3.1: 9.8
Description: The web interface deserialises untrusted data. An unauthenticated remote attacker could execute arbitrary code on the affected system.
Impact: Arbitrary code execution on the ClearPass system.
Conditions: Unauthenticated remote access to the affected web interface.
Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.
CVE-2026-76751 - OnGuard integrity verification failure
Severity: Critical
CVSS v3.1: 9.8
Description: Missing integrity verification affects the OnGuard agent. An unauthenticated remote attacker could execute arbitrary code on an affected endpoint.
Impact: Endpoint code execution with the elevated privileges of the agent.
Conditions: Unauthenticated remote attack against an affected OnGuard agent.
Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.
CVE-2026-76752 - Management and API authentication bypass
Severity: Critical
CVSS v3.1: 9.8
Description: Authentication bypass flaws affect the web-based management and API interfaces. An unauthenticated remote attacker could circumvent authentication controls.
Impact: Unauthorised administrative access to the affected system.
Conditions: Unauthenticated remote access to an affected management or API interface.
Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.
CVE-2026-76753 - Format string flaw and remote code execution
Severity: Critical
CVSS v3.1: 9.8
Description: A format string flaw in an affected service interface could allow an unauthenticated remote attacker to corrupt process memory. Successful exploitation could allow arbitrary code execution.
Impact: Process memory corruption and potential arbitrary code execution.
Conditions: Unauthenticated remote access to the affected service interface.
Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.
CVE-2026-76754 - Unauthenticated SQL injection
Severity: Critical
CVSS v3.1: 9.8
Description: SQL injection affects an interface of ClearPass Policy Manager. An unauthenticated remote attacker could run arbitrary database commands.
Impact: Arbitrary database commands. HPE titles this flaw as leading to remote code execution.
Conditions: Unauthenticated remote access to the affected interface.
Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.
CVE-2026-79796 - Authentication bypass
Severity: Critical
CVSS v3.1: 9.8
Description: Flaws in an affected ClearPass interface could allow an unauthenticated remote attacker to circumvent authentication controls.
Impact: Unauthorised access to the affected system.
Conditions: Unauthenticated remote access to the affected interface.
Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.
CVE-2026-79801 - Client-agent integrity verification failure
Severity: Critical
CVSS v3.1: 9.8
Description: Missing integrity verification in the client-agent software could allow an unauthenticated remote attacker to introduce untrusted code.
Impact: Arbitrary code execution on an affected client system.
Conditions: Unauthenticated remote attack against the affected client-agent software.
Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.
CVE-2026-79805 - Path traversal and unauthorised file access
Severity: Critical
CVSS v3.1: 9.8
Description: HPE describes an authenticated path traversal flaw in ClearPass Policy Manager. Successful exploitation could allow an attacker to read and modify certain files on the underlying operating system.
Impact: Unauthorised access to and modification of certain operating system files.
Conditions: HPE describes authenticated exploitation, but its published CVSS vector lists PR:N, meaning no privileges required. HPE does not reconcile this inconsistency. The score is reproduced as published; no privilege level is inferred.
Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.
CVE-2026-79794 - High-privileged SQL injection
Severity: Critical
CVSS v3.1: 9.1
Description: SQL injection affects the web-based management interface. An authenticated remote attacker could run arbitrary database commands.
Impact: Arbitrary database commands, risking database confidentiality, integrity and availability.
Conditions: Authenticated remote access. HPE’s CVSS vector specifies high privileges and no user interaction.
Affected and fixed versions: The shared CPPM release mapping in Affected Versions applies to this CVE.
Mitigation
Upgrade immediately: Move affected deployments to CPPM 6.14.1 or later in the 6.14 branch, or 6.11.16 or later in the 6.11 branch, as applicable. Obtain the vendor software from the HPE Networking Support Portal, following the security bulletin resolution.
Account for endpoint exposure: Include OnGuard and client-agent software in remediation planning. HPE identifies endpoint code-execution risks as well as server-side flaws in the bulletin. Confirm the appropriate client packages and deployment procedure with HPE; do not assume patching a server automatically updates installed agents.
Restrict management access while remediation proceeds: HPE recommends a dedicated layer 2 segment/VLAN and/or layer 3 and above firewall policies for CLI and web-based management interfaces. Apply accounting controls to track and log user activities and resource usage. This is HPE’s risk-reduction workaround, not a replacement for the required software updates.
Review upgrade and hardening guidance: Consult the 6.14.1 release notes or 6.11.16 release notes and the relevant 6.14 Hardening Guide or 6.11 Hardening Guide.
Summary for IT Teams
Products: HPE ClearPass Policy Manager, affected OnGuard and client-agent software.
Threat Level: Critical, CVSS v3.1 9.1 to 9.9 for the ten highlighted CVEs.
Action Required: Prioritise the applicable 6.14.1 or 6.11.16 update, confirm endpoint-agent remediation, restrict management interfaces and retain activity logs. Refer to the HPE remediation guidance.
Reference
Need Help?
Please get in touch on 1300 769 460 or email the Secure ISS SOC team. We are here to help you strengthen your cybersecurity posture.

