Junglewise Threat Intelligence

CVE-2026-76714: HPE Analytics and Location Engine command injection in web interface

CVE-2026-76714 · Severity: high · CVSS 7.2 · Published 2026-09-22

Vendors: Hpe.

Executive brief

The Analytics and Location Engine web interface allows authenticated users to inject and execute arbitrary commands on the host system with root privileges. A successful attack could give an attacker complete control over the server, enabling data theft, service disruption, or use as a platform for further attacks.

Technical details

The web interface contains a command injection vulnerability that allows authenticated users to execute arbitrary OS commands as root. The vulnerability is reachable over the network from users with valid credentials, and no additional user interaction is required beyond authentication.

Affected products

  • HPE Analytics and Location Engine

Timeline

  • 2026-09-22: disclosed

References

Related threats