HPE security advisory (AV26-909)
HPE's ClearPass and IceWall security tools have flaws that let attackers crash them or hijack user sessions. This affects Canadian government and business networks.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Fixed in 6.11.15
- Exploited
- Not confirmedNo confirmation recorded
How it works
- Attackers send specially crafted requests to ClearPass Policy Manager or IceWall.
- These requests trick the software into misreading its own data, causing crashes or session hijacking.
- The flaws let attackers take over user accounts or stop the tools from working.
What to do
Check if you use HPE ClearPass Policy Manager or IceWall. If you're running ClearPass 6.11.14 or earlier, or 6.12.8 or earlier, you're affected. For IceWall, any version may be vulnerable. Review your installed versions in the product's admin console or contact HPE support for help.
Update ClearPass Policy Manager to 6.11.15 or 6.12.9. For IceWall, apply the latest patch from HPE's advisory. Check the HPE support portal for updates or contact HPE support if unsure.
Technical details
HPE disclosed multiple vulnerabilities in ClearPass Policy Manager (CPPM) and HPE IceWall products, affecting versions up to 6.11.14, 6.12.8, and unspecified IceWall models. These flaws allow attackers to bypass authentication controls, execute unauthorized commands, or escalate privileges, potentially gaining full system access. The vulnerabilities were assigned the internal identifier NEWS-f31eb99340a424b93d and were reported to HPE on September 9, 2026. Affected users are urged to apply available patches or updates to mitigate risk.
References
- support.hpe.com · docDisplay CCCS Canada
- support.hpe.com · securitybulletinlibrary CCCS Canada