Junglewise Threat Intelligence

CVE-2026-23600: HPE AutoPass License Server remote authentication bypass

CVE-2026-23600 · Severity: critical · CVSS 9.8 · Published 2026-03-02

Vendors: Hpe.

Executive brief

HPE AutoPass License Server (APLS) is used to manage software licenses and control access to HPE enterprise products. A remote authentication bypass vulnerability allows attackers to bypass login controls without valid credentials, potentially gaining unauthorized access to license management systems and sensitive customer data.

Technical details

A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS). The vulnerability allows an unauthenticated attacker on the network to bypass authentication mechanisms and gain unauthorized access to the system. Attack exploitation does not require user interaction and can be triggered directly over the network. An attacker can leverage this to access license management functions, potentially modify licenses, access customer information, or cause denial of service. Patches should be available from HPE support.

Affected products

  • HPE AutoPass License Server <UNKNOWN>

Timeline

  • 2026-03-02: disclosed

References