CVE-2026-76725: Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs
Published Sep 29, 2026
·Updated
A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code execution with elevated privileges.
Affected Software
1 affected component
HPE Networking Instant On APs
Event History
Sep 29, 2026
CVE Published
via MITRE·07:28 PM
Data Sourced
via MITRE·07:28 PM
DescriptionSeverity
Data Sourced
via NVD·08:17 PM
DescriptionSeverity
Frequently Asked Questions
1
Who is exposed to exploitation?
HPE Networking Instant On APs are exposed when an attacker can access the adjacent network. The attacker does not need prior authentication or user interaction.
2
What could an attacker achieve after exploiting the issue?
Successful exploitation can bypass existing authentication controls and security restrictions. It could potentially lead to remote code execution with elevated privileges.