Remote Code Execution Vulnerability in ClearPass Policy Manager Could Lead to Complete System Compromise
CVE-2024-26294
What is CVE-2024-26294?
A vulnerability exists in the ClearPass Policy Manager web-based management interface that permits remote authenticated users to execute arbitrary commands on the underlying operating system. This security flaw could potentially enable an attacker to gain root access, thereby compromising the entire system. Organizations utilizing this product must prioritize patching and monitoring systems to mitigate risks associated with unauthorized command execution.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Aruba ClearPass Policy Manager ClearPass Policy Manager 6.12.x: 6.12.0
Aruba ClearPass Policy Manager ClearPass Policy Manager 6.12.x: 6.12.0
Aruba ClearPass Policy Manager ClearPass Policy Manager 6.11.x: 6.11.6 and below
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved