External risk intelligence

HPE ClearPass Client Agent Code Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-79801

The vulnerability affects client agent software. Client agents are typically installed on end-user devices or managed systems and are generally not exposed directly to the public internet, usually residing behind internal network controls or corporate perimeters.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability discovered in HPE's ClearPass Policy Manager client agent software. The issue involves a missing integrity check that could permit an unauthorized remote attacker to insert malicious code, potentially leading to the execution of arbitrary code on affected systems. The primary concern at this time is to confirm whether this technology is in use within our environment.

  • Flaw allows remote code injection.
  • Could impact client agent software.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could leverage this vulnerability by sending specially crafted network requests to the vulnerable client agent software, even without prior authentication. This could lead to the introduction of untrusted code, potentially allowing the attacker to execute arbitrary code on the affected system.

  • Unauthenticated remote network access required.
  • Client agent software is the trigger point.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to execute arbitrary code on an affected client system by introducing untrusted code due to a missing integrity verification.

  • Arbitrary code execution on client systems.
  • Untrusted code introduction via network.
  • Compromise of client system integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in HPE Networking ClearPass Policy Manager client agent software requires immediate attention from the relevant system owners and security teams. The first step is to identify all instances of the affected client agent, assess their exposure and business criticality, and confirm the accountable team for remediation. Subsequently, a risk-based remediation plan should be developed and executed.

  • Ownership by infrastructure and security teams.
  • Verify agent reachability and criticality.
  • Plan targeted remediation and monitoring.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the HPE Networking ClearPass Policy Manager client agent?

HPE Networking ClearPass Policy Manager is a platform used by organizations to manage and secure network access. The client agent is a software component installed on individual end-user devices or systems that facilitates communication between the device and the ClearPass server, ensuring the device meets organizational security policies before it is granted network access.

What does the missing integrity verification mean in CVE-2026-79801?

This vulnerability refers to a weakness where the software fails to properly confirm that data or instructions it receives are legitimate and unmodified. Because the agent does not verify the source or integrity of incoming communications, it can be tricked into accepting and running unauthorized, untrusted code provided by an attacker, leading to arbitrary code execution.

How does an attacker trigger this vulnerability?

An attacker triggers the flaw by sending specially crafted network requests directly to the ClearPass client agent. The vulnerability relies on the agent being reachable over the network to receive these inputs. It is not triggered by standard, authorized interactions with the ClearPass server, but rather by malicious, unauthenticated traffic directed at the agent.

Do I need to worry if my agent is not on the internet?

According to Halo Surface Signal, this risk is generally lower if your agents reside behind internal network controls rather than being directly exposed to the public internet. Since the flaw requires remote network access to the agent, systems isolated within a secure corporate perimeter are less reachable to the external attackers who would attempt to exploit this bug.

What is the first step to address CVE-2026-79801?

Begin by identifying all systems in your environment that have the HPE ClearPass client agent installed. Once you have a complete inventory, determine which of these systems are critical to your business operations and assess their network reachability. Coordinate with the teams responsible for those assets to monitor for unusual activity and prepare for the necessary security updates.

References