CVE-2026-76715: Unauthenticated Man-in-the-Middle Attach Leads to Remote Code Execution Vulnerability in HPE Networking Analytics and Location Engine (ALE)
Published Sep 22, 2026
·Updated
A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-middle (MitM) attack. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the affected appliance.
Affected Software
1 affected component
HPE Networking Analytics and Location Engine (ALE)
Event History
Sep 22, 2026
CVE Published
via MITRE·07:12 PM
Data Sourced
via MITRE·07:12 PM
DescriptionSeverity
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access or conditions does an attacker need to exploit this issue?
The attacker does not need authentication, but exploitation requires a man-in-the-middle position and user interaction. The attack vector is adjacent-network rather than broadly reachable over the Internet.
2
What level of access could successful exploitation provide?
Successful exploitation could allow arbitrary code execution with root privileges on the affected ALE appliance.