Executive brief
HPE Analytics and Location Engine (ALE) is a network visibility and location tracking system used by enterprises to monitor devices and assets. A vulnerability in its maintenance restore functionality allows authenticated remote attackers to execute commands with root privileges, potentially taking complete control of the system and accessing all data it manages.
Technical details
The vulnerability exists in the maintenance restore functionality of ALE and allows an authenticated remote attacker to gain root-level file system access. This represents a privilege escalation flaw reachable by authenticated users, leading to full system compromise through arbitrary code execution with elevated privileges.
Affected products
- HPE Analytics and Location Engine
Timeline
- 2026-09-22: disclosed