CVE-2026-79802: Command Injection Vulnerability in the ClearPass Policy Manager Client Software
Published Oct 6, 2026
·Updated
A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted input to the affected software to execute arbitrary commands with elevated privileges on the affected host.
Affected Software
1 affected component
Aruba Networks ClearPass Policy Manager Client Software
Event History
Oct 6, 2026
CVE Published
via MITRE·07:17 PM
Data Sourced
via MITRE·07:17 PM
DescriptionSeverity
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an authenticated account?
No. The CVSS vector indicates no privileges are required, although the attacker must be able to provide crafted input to the affected client software.
2
Is user interaction required for exploitation?
Yes. The CVSS vector indicates user interaction is required. Successful exploitation can result in arbitrary command execution with elevated privileges on the affected host.