CVE-2026-79799: Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in ClearPass Policy Manager Web-Based Management Interface
Published Oct 6, 2026
·Updated
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Affected Software
1 affected component
Aruba ClearPass Policy Manager
Event History
Oct 6, 2026
CVE Published
via MITRE·07:17 PM
Data Sourced
via MITRE·07:17 PM
DescriptionSeverity
Data Sourced
via NVD·08:17 PM
DescriptionSeverity