Junglewise Threat Intelligence

CVE-2026-73789: HPE CPPM guest account management web interface authentication bypass

CVE-2026-73789 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Vendors: Hpe.

Executive brief

HPE CPPM (Converged Platform and Policy Manager) includes a web-based interface for managing guest account access to corporate networks. This vulnerability allows unauthenticated attackers to modify guest account settings remotely, enabling them to extend network access beyond intended time limits and bypass policy controls. Organizations using CPPM for guest access management could see unauthorized users maintaining network connectivity and consuming resources beyond approved periods.

Technical details

The web-based management interface for CPPM guest account services fails to properly enforce authentication controls on account manipulation functions. An unauthenticated remote attacker can send crafted requests to modify guest account settings, including access duration and policies. The vulnerability is reachable over the network without prior authentication or user interaction. Successful exploitation allows attackers to extend guest account validity periods beyond policy limits, effectively granting unauthorized prolonged network access. Patches are expected from HPE; consult the vendor advisory for availability and remediation guidance.

Affected products

  • HPE CPPM <UNKNOWN>

Timeline

  • 2026-09-09: disclosed

References

Related threats