Skip to content
VulniPulse

HPE Aruba Networking ClearPass (NAC) Vulnerabilities & Security Advisories

48 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published HPE Aruba Networking advisory that VulniPulse classified as ClearPass (NAC), with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 10 critical, 19 high, 19 medium.

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba ClearPass (NAC) advisories

High7.2Aruba Updated

High [CVE-2026-79811] ClearPass Policy Manager: SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote authenticated attacker with administrative privileges to conduct SQL injection attacks against the ClearPass Policy Manager instance

A SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote authenticated attacker with administrative privileges to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to execute arbitrary database commands. Affected product named by the advisory: ClearPass Policy Manager (CPPM).

CVE-2026-79811
ClearPassClearPass Policy Manager
Oct 6, 2026
High7.2Aruba Updated

High [CVE-2026-79810] ClearPass Policy Manager: Remote code execution vulnerabilities exist in the affected interface of HPE Networking ClearPass Policy Manager that could allow an authenticated remote attacker with high privileges to execute arbitrary code

Remote code execution vulnerabilities exist in the affected interface of HPE Networking ClearPass Policy Manager that could allow an authenticated remote attacker with high privileges to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. Affected product named by the advisory: ClearPass Policy Manager (CPPM).

CVE-2026-79810
ClearPassClearPass Policy Manager
Oct 6, 2026
High7.3Aruba Updated

High [CVE-2026-79809] ClearPass Policy Manager: unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager

An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability allows an unauthenticated remote attacker to influence authorization decisions and be assigned an unintended role. Affected product named by the advisory: ClearPass Policy Manager (CPPM).

CVE-2026-79809
ClearPassClearPass Policy Manager
Oct 6, 2026
High7.8Aruba Updated

High [CVE-2026-79808] ClearPass Policy Manager: buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager

A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an authenticated local user to execute arbitrary code with elevated privileges on the affected host or to disrupt the availability of the affected service. Affected product named by the advisory: ClearPass Policy Manager (CPPM).

CVE-2026-79808
ClearPassClearPass Policy Manager
Oct 6, 2026
High7.8Aruba Updated

High [CVE-2026-79807] ClearPass Policy Manager: missing integrity verification vulnerability in the Windows client software for ClearPass Policy Manager could allow malicious users on a local instance to elevate their user privileges

A missing integrity verification vulnerability in the Windows client software for ClearPass Policy Manager could allow malicious users on a local instance to elevate their user privileges. A successful exploit could allow these users to execute attacker-supplied code with elevated privileges on the local system. Affected product named by the advisory: ClearPass Policy Manager (CPPM).

CVE-2026-79807
ClearPassClearPass Policy Manager
Oct 6, 2026
High7.8Aruba Updated

High [CVE-2026-79806] ClearPass Policy Manager: privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges

A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit allows a malicious user to escalate to root privileges on the affected Linux client. Affected product named by the advisory: ClearPass Policy Manager (CPPM).

CVE-2026-79806
ClearPassClearPass Policy Manager
Oct 6, 2026
High8.8Aruba Updated

High [CVE-2026-79803] ClearPass Policy Manager: command injection vulnerability exists in the API of ClearPass Policy Manager

A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploitation could allow an authenticated remote attacker to escalate privileges and gain administrative control of the affected system. Affected product named by the advisory: ClearPass Policy Manager (CPPM).

CVE-2026-79803
ClearPassClearPass Policy Manager
Oct 6, 2026
High8.8Aruba Updated

High [CVE-2026-79802] ClearPass Policy Manager: command injection vulnerability exists in the client software of ClearPass Policy Manager

A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted input to the affected software to execute arbitrary commands with elevated privileges on the affected host. Affected product named by the advisory: ClearPass Policy Manager (CPPM).

CVE-2026-79802
ClearPassClearPass Policy Manager
Oct 6, 2026
High8.8Aruba Updated

High [CVE-2026-79800] ClearPass Policy Manager: authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager

An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager. Successful exploitation could allow a low-privileged authenticated remote attacker to execute arbitrary code with elevated privileges on the underlying operating system. Affected product named by the advisory: ClearPass Policy Manager (CPPM).

CVE-2026-79800
ClearPassClearPass Policy Manager
Oct 6, 2026
High8.8Aruba Updated

High [CVE-2026-79799] ClearPass Policy Manager: vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. Affected product named by the advisory: ClearPass Policy Manager (CPPM).

CVE-2026-79799
ClearPassClearPass Policy Manager
Oct 6, 2026
High8.8Aruba Updated

High [CVE-2026-79797] ClearPass Policy Manager: improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources

An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthenticated remote attacker, with user interaction, to obtain sensitive information from the affected user. Affected product named by the advisory: ClearPass Policy Manager (CPPM).

CVE-2026-79797
ClearPassClearPass Policy Manager
Oct 6, 2026
High7.2Aruba

High [CVE-2026-73787] Authenticated Arbitrary File Write allows Remote Code Execution via CPPM Web Interface

A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information on a vulnerable system. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. Affected product named by the advisory: ClearPass Policy Manager (CPPM).

CVE-2026-73787
ClearPassWireless & ControllersClearPass Policy Manager
Sep 9, 2026
High7.5Aruba

High [CVE-2026-73786] Unauthenticated Network-Based Denial of Service in CPPM systems

A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attacker to cause instability and degrade performance of the vulnerable CPPM server. Affected product named by the advisory: ClearPass Policy Manager (CPPM).

CVE-2026-73786
ClearPassClearPass Policy Manager
Sep 9, 2026
High7.2Aruba

High [CVE-2026-73769] Authenticated Remote Code Execution in CPPM Web Interface

A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. Affected product named by the advisory: ClearPass Policy Manager (CPPM).

CVE-2026-73769
ClearPassClearPass Policy Manager
Sep 9, 2026
High7.8Aruba

High [CVE-2026-23599] local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software for Linux

A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software for Linux. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges.

CVE-2026-23599
ClearPass
Feb 18, 2026
High8.8Aruba

High [CVE-2025-23058] vulnerability in the ClearPass Policy Manager web-based management interface

A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the ability to execute functions that should be restricted to administrators only with read/write privileges. Successful exploitation could enable a low-privileged user to execute administrative functions leading to an escalation of privileges.

CVE-2025-23058
ClearPassClearPass Policy Manager
Feb 4, 2025
High7.2Aruba

High [CVE-2024-51771] vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could

A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation could enable the attacker to run arbitrary commands on the underlying operating system.

CVE-2024-51771
ClearPassClearPass Policy Manager
Dec 3, 2024
High7.2Aruba

High [CVE-2024-41915] vulnerability in the web-based management interface of ClearPass Policy Manager could

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster.

CVE-2024-41915
ClearPassClearPass Policy Manager
Jul 30, 2024
High7.2Aruba

High [CVE-2024-26298] Vulnerabilities in the ClearPass Policy Manager web-based management interface

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.

CVE-2024-26298
ClearPassClearPass Policy Manager
Feb 27, 2024

← All Aruba advisories