CVE-2026-79797: Improper Access Control in HPE Networking ClearPass Android Client Application
An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthenticated remote attacker, with user interaction, to obtain sensitive information from the affected user.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of the HPE ClearPass Policy Manager Android Client Application are the affected population. Exploitation targets sensitive information available to the affected user.
What does an attacker need to exploit it?
The attacker can be remote and does not need authentication, but user interaction is required. The issue involves application functionality being invoked by untrusted sources.
What is the potential impact of successful exploitation?
A successful attack could allow the attacker to obtain sensitive information from the affected user. The reported severity is high, with impacts to confidentiality, integrity, and availability.