hewlett-packard-enterpriseCVE-2026-76714
Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary commands on the underlying host.
High7.2CVE-2026-76714 · Published Sep 22, 2026 · updated Sep 23, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| ALE Vendor | >= 0.0.0.0, <= 5.0.0.0 | No fix yet |
Details and references
Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Severity from
- no source yet
- Weakness
- CWE-78