Junglewise Threat Intelligence

CVE-2026-76712: HP Analytics and Location Engine unauthorized access and denial of service

CVE-2026-76712 · Severity: high · CVSS 7.3 · Published 2026-09-22

Vendors: Hp.

Executive brief

HP's Analytics and Location Engine (ALE) is a network location and analytics platform used in enterprise environments. A vulnerability allows unauthenticated remote attackers to gain unauthorized access, disclose sensitive information, or disrupt service availability by sending specially crafted network requests. Successful exploitation could expose location data, bypass security controls, or cause service outages.

Technical details

An unauthenticated remote vulnerability in Analytics and Location Engine (ALE) permits attackers to send specially crafted input or intercept network communications to achieve unauthorized access, information disclosure, or denial of service. The vulnerability is exploitable over the network without authentication or user interaction. Exploitation results in disclosure of sensitive data, security control bypass, or service unavailability.

Affected products

  • HP Analytics and Location Engine

Timeline

  • 2026-09-22: disclosed

References