CVE-2026-79807: Authenticated Local Missing Integrity Verification Vulnerability leads to Local Privilege Escalation in the ClearPass Policy Manager Windows Client Software
Published Oct 6, 2026
·Updated
A missing integrity verification vulnerability in the Windows client software for ClearPass Policy Manager could allow malicious users on a local instance to elevate their user privileges. A successful exploit could allow these users to execute attacker-supplied code with elevated privileges on the local system.
Affected Software
1 affected component
Aruba Networks ClearPass Policy Manager Windows Client Software
Event History
Oct 6, 2026
CVE Published
via MITRE·07:17 PM
Data Sourced
via MITRE·07:17 PM
DescriptionSeverity
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Can this be exploited remotely without access to the affected system?
The available CVSS data identifies the attack vector as local. Exploitation requires an attacker to have low-privileged access on the local system and does not require user interaction.