CVE-2026-79801: Unauthenticated Missing Integrity Verification allows Remote Code Execution in ClearPass Policy Manager Client Agent
A missing integrity verification vulnerability in the client agent software of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to introduce untrusted code. Successful exploitation could allow an attacker to execute arbitrary code on the affected client system.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems running the HPE Networking ClearPass Policy Manager Client Agent are affected. The available information identifies the client system, rather than the ClearPass Policy Manager server, as the system on which arbitrary code could execute.
Does exploitation require credentials or user interaction?
No. The vulnerability is described as exploitable by an unauthenticated remote attacker, with no privileges or user interaction required.
What could an attacker achieve?
An attacker could introduce untrusted code and execute arbitrary code on the affected client system. The stated impact includes high confidentiality, integrity, and availability impact.