Hewlett Packard EnterpriseCVE-2026-76727
Hewlett Packard Enterprise Instant ON: command injection
High7.2CVE-2026-76727 · Published Sep 29, 2026 · updated Oct 1, 2026
Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Instant ON Product | >= 0.0.0.0, <= 3.4.1.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-77
More Hewlett Packard Enterprise advisories
All Hewlett Packard Enterprise| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 29 | Hewlett Packard Enterprise Instant ON: buffer overflow | Low3.3 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: path traversal | Low3.0 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: buffer overflow | Low2.7 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: memory corruption | Medium6.6 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: authentication bypass | Medium6.5 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: authentication bypass | Medium6.5 | No fix yet |