Hewlett Packard EnterpriseCVE-2026-76726
Hewlett Packard Enterprise Instant ON: authentication bypass
High8.1CVE-2026-76726 · Published Sep 29, 2026 · updated Oct 1, 2026
An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to obtain unauthorized access to restricted networks.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Instant ON Product | >= 0.0.0.0, <= 3.4.1.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-287
More Hewlett Packard Enterprise advisories
All Hewlett Packard Enterprise| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 29 | Hewlett Packard Enterprise Instant ON: buffer overflow | Low3.3 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: path traversal | Low3.0 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: buffer overflow | Low2.7 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: memory corruption | Medium6.6 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: authentication bypass | Medium6.5 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: authentication bypass | Medium6.5 | No fix yet |