Junglewise Threat Intelligence

CVE-2026-73778: HPE Credential Manager predictable password vulnerability

CVE-2026-73778 · Severity: high · CVSS 8.1 · Published 2026-09-01

Vendors: Hpe.

Executive brief

HPE devices include a Credential Manager component that manages administrative authentication during initial setup. An attacker can gain full administrative control of an uninitialized device by using a predictable factory-default password, bypassing all access controls and enabling complete device compromise before the administrator has configured proper credentials.

Technical details

The vulnerability exists in the Credential Manager component which fails to enforce strong authentication on factory-default or post-Zero-Touch Provisioning (ZTP) devices. The root cause is the use of a predictable factory-default password that is not changed until an administrator explicitly configures credentials. An unauthenticated remote attacker can exploit this by connecting to the device during initial setup and providing the known default password, gaining unrestricted administrative access. No special preconditions or user interaction is required beyond the device being in its unconfigured state. Successful exploitation grants full administrative control, allowing complete device compromise including configuration modification, data access, and persistence mechanisms.

Affected products

  • HPE Credential Manager

Timeline

  • 2026-09-01: disclosed

References