A vulnerability in the web-based management interface of CPPM guest account management services could allow an unauthenticated remote attacker to manipulate account settings. Successful exploitation could allow an attacker to extend network access beyond policy limits, leading to unauthorized prolonged use of network resources.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-287 |
Wed, 09 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the web-based management interface of CPPM guest account management services could allow an unauthenticated remote attacker to manipulate account settings. Successful exploitation could allow an attacker to extend network access beyond policy limits, leading to unauthorized prolonged use of network resources. | |
| Title | Unauthenticated Insecure Parameter Manipulation allows Data Tampering In CPPM Web Interface | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hpe
Published: 2026-09-09T19:15:21.899Z
Updated: 2026-09-09T19:15:21.899Z
Reserved: 2026-08-13T16:39:33.899Z
Link: CVE-2026-73789
No data.
Status : Received
Published: 2026-09-09T20:20:33.830
Modified: 2026-09-09T20:20:33.830
Link: CVE-2026-73789
No data.