CVE-2026-76737: Authenticated Local Path Traversal Vulnerability Leads to Denial-of-Service in HPE Networking Instant On
Published Sep 29, 2026
·Updated
An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.
Affected Software
1 affected component
HPE Networking Instant ON
Event History
Sep 29, 2026
CVE Published
via MITRE·07:28 PM
Data Sourced
via MITRE·07:28 PM
DescriptionSeverity
Data Sourced
via NVD·08:17 PM
DescriptionSeverity
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires authenticated administrative access to the HPE Networking Instant On command line interface. It is a local attack vector and does not require user interaction.
2
What impact can an attacker achieve?
An attacker may modify a limited set of files on the underlying operating system and interrupt normal operation of the affected service. The provided severity vector indicates no confidentiality impact, with low integrity and availability impact.