CVE-2026-79815: Authenticated Command Injection Vulnerability in the ClearPass Policy Manager OnGuard Agent
A command injection vulnerability in the OnGuard agent of ClearPass Policy Manager could allow an authenticated remote attacker to inject arbitrary commands. Successful exploitation could allow an attacker to execute commands with elevated privileges on the affected Windows endpoint.
Affected Software
Event History
Frequently Asked Questions
Which endpoints are in scope?
The affected software is the Aruba Networks ClearPass Policy Manager OnGuard Agent, and the described impact is on affected Windows endpoints.
Does an attacker need to authenticate before exploiting this issue?
The description says the attacker must be authenticated, while the supplied CVSS vector lists privileges required as none (PR:N). This creates an inconsistency in the provided data; authentication requirements should be verified against the vendor advisory.
What level of access could successful exploitation provide?
Successful exploitation could let an attacker execute arbitrary injected commands with elevated privileges on the affected Windows endpoint.