Remote User Validation Flaw in HPE Integrated Lights-Out Firmware
CVE-2026-79820

9CRITICAL

Key Information:

Vendor

HP (HP)

Vendor
CVE Published:
5 October 2026

What is CVE-2026-79820?

A vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware that could allow a remote user to bypass authentication mechanisms. This issue may lead to unauthorized access and manipulation of critical system settings, posing potential risks to the integrity and security of affected systems. Organizations utilizing this firmware should take appropriate measures to address this vulnerability and ensure their systems are protected against unauthorized access.

Affected Version(s)

HPE Integrated Lights-Out (iLO) 7 1.25.00

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.