CVE-2026-79800: Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in ClearPass Policy Manager
Published Oct 6, 2026
·Updated
An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager. Successful exploitation could allow a low-privileged authenticated remote attacker to execute arbitrary code with elevated privileges on the underlying operating system.
Affected Software
1 affected component
Aruba Networks ClearPass Policy Manager
Event History
Oct 6, 2026
CVE Published
via MITRE·07:17 PM
Data Sourced
via MITRE·07:17 PM
DescriptionSeverity
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require user interaction?
No. The CVSS vector indicates that no user interaction is required.
2
Is the vulnerable interface reachable remotely?
Yes. The CVSS vector identifies the attack vector as network-based, and the issue affects the command line interface.
3
What is the expected impact if exploitation succeeds?
The vulnerability is rated high severity with high impact to confidentiality, integrity, and availability. Successful exploitation can result in arbitrary code execution with elevated operating-system privileges.