CVE-2026-76753: Unauthenticated Format String Vulnerability in HPE Networking ClearPass Policy Manager
Published Oct 6, 2026
·Updated
A format string vulnerability in an affected service interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to corrupt process memory. Successful exploitation could allow an attacker to execute arbitrary code.
Affected Software
1 affected component
HPE ClearPass Policy Manager
Event History
Oct 6, 2026
CVE Published
via MITRE·07:16 PM
Data Sourced
via MITRE·07:16 PM
DescriptionSeverity
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require user interaction or a valid account?
No. The vulnerability is rated as requiring no privileges and no user interaction.
2
How difficult is exploitation expected to be?
The vulnerability is rated as network-accessible with low attack complexity. Its CVSS vector rates confidentiality, integrity, and availability impact as high.