Junglewise Threat Intelligence

CVE-2026-76713: HPE Analytics and Location Engine privilege escalation in maintenance restore

CVE-2026-76713 · Severity: high · CVSS 7.2 · Published 2026-09-22

Vendors: Hpe.

Executive brief

HPE Analytics and Location Engine (ALE) is a network visibility and location tracking system used by enterprises to monitor devices and assets. A vulnerability in its maintenance restore functionality allows authenticated remote attackers to execute commands with root privileges, potentially taking complete control of the system and accessing all data it manages.

Technical details

The vulnerability exists in the maintenance restore functionality of ALE and allows an authenticated remote attacker to gain root-level file system access. This represents a privilege escalation flaw reachable by authenticated users, leading to full system compromise through arbitrary code execution with elevated privileges.

Affected products

  • HPE Analytics and Location Engine

Timeline

  • 2026-09-22: disclosed

References

Related threats