Executive brief
The Analytics and Location Engine web interface allows authenticated users to inject and execute arbitrary commands on the host system with root privileges. A successful attack could give an attacker complete control over the server, enabling data theft, service disruption, or use as a platform for further attacks.
Technical details
The web interface contains a command injection vulnerability that allows authenticated users to execute arbitrary OS commands as root. The vulnerability is reachable over the network from users with valid credentials, and no additional user interaction is required beyond authentication.
Affected products
- HPE Analytics and Location Engine
Timeline
- 2026-09-22: disclosed