Unauthorized Access Risk in CPPM Guest Account Management by HPE
CVE-2026-73789
5.3MEDIUM
What is CVE-2026-73789?
The CPPM Guest Account Management services feature a vulnerability in its web-based management interface that permits unauthenticated remote attackers to alter account settings. By exploiting this flaw, attackers can manipulate guest accounts to extend their network access beyond established policies, resulting in unauthorized and potentially prolonged usage of network resources. This situation poses serious security risks that necessitate immediate attention and remediation.
Affected Version(s)
ClearPass Policy Manager (CPPM) 6.12.0 <= 6.12.8
ClearPass Policy Manager (CPPM) 6.12.0 <= 6.12.8
ClearPass Policy Manager (CPPM) 6.11.0 <= 6.11.14
