Hewlett Packard EnterpriseCVE-2026-76732
Hewlett Packard Enterprise Instant ON: privilege escalation
Medium6.4CVE-2026-76732 · Published Sep 29, 2026 · updated Oct 1, 2026
A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Instant ON Product | >= 0.0.0.0, <= 3.4.1.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-269
More Hewlett Packard Enterprise advisories
All Hewlett Packard Enterprise| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 29 | Hewlett Packard Enterprise Instant ON: buffer overflow | Low3.3 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: path traversal | Low3.0 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: buffer overflow | Low2.7 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: memory corruption | Medium6.6 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: authentication bypass | Medium6.5 | No fix yet |
| Sep 29 | Hewlett Packard Enterprise Instant ON: authentication bypass | Medium6.5 | No fix yet |