CVE-2026-76727: Authenticated Command Injection Vulnerabilities in HPE Networking Instant ON
Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be able to reach the affected HPE Networking Instant ON interface remotely and authenticate with high privileges. The available information does not indicate that unauthenticated or low-privileged users can exploit it.
What could successful exploitation allow?
A successful attacker could inject and execute arbitrary commands as a privileged user on the underlying operating system. This can affect confidentiality, integrity, and availability.
Is a default deployment known to be affected?
The provided information confirms that the affected interface is vulnerable, but does not state whether it is enabled or exposed in a default configuration.
How can I determine whether my environment is affected?
Identify HPE Networking Instant ON deployments and review the vendor advisory referenced in the vulnerability record for affected-interface and remediation details. The provided data does not include affected versions or a detection method.