Authentication Bypass Vulnerability in HPE Networking Instant On
CVE-2026-76731

6.5MEDIUM

Key Information:

Vendor

HP (HP)

Vendor
CVE Published:
29 September 2026

What is CVE-2026-76731?

An authentication bypass vulnerability has been identified in the captive portal of HPE Networking Instant On. This flaw enables an unauthenticated remote attacker to bypass existing authentication measures, potentially leading to unauthorized access to limited data and allowing basic modifications within the affected component. Organizations using HPE Networking Instant On should take immediate steps to evaluate their security posture and apply recommended patches.

Affected Version(s)

Instant ON 0.0.0.0 <= 3.4.1.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Internal security research (HPE Networking).
.