CVE-2026-76713: Authenticated Remote File System Access Vulnerability in HPE Networking Analytics and Location Engine (ALE)
A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file system with root privileges, potentially resulting in full system compromise.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated and able to access ALE remotely. The provided information does not identify which authenticated roles or accounts are sufficient.
What level of access could successful exploitation provide?
Successful exploitation could give the attacker unauthorized file-system access with root privileges. This could result in full compromise of the affected system.
Which ALE configurations or versions are affected?
The provided information does not specify affected versions, fixed versions, or whether the maintenance restore functionality is enabled by default.