Hewlett Packard EnterpriseCVE-2026-76731
Hewlett Packard Enterprise Instant ON: authentication bypass
Medium6.5CVE-2026-76731 · Published Sep 29, 2026 · updated Sep 30, 2026
An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain limited access to some data and to make limited changes within the affected component.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Instant ON Product | >= 0.0.0.0, <= 3.4.1.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-269
More Hewlett Packard Enterprise advisories
All Hewlett Packard Enterprise| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 29 | Hewlett Packard Enterprise Instant ON: buffer overflow | Low3.3 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: path traversal | Low3.0 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: buffer overflow | Low2.7 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: memory corruption | Medium6.6 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: authentication bypass | Medium6.5 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: privilege escalation | Medium6.4 | No fix yet |