logo

HPE AutoPass Vulnerability Let Attackers Bypass Authentication Remotely

ID: 1d47d964-cf6c-5391-93b7-700992f7c0f2

STIX ID: report--1d47d964-cf6c-5391-93b7-700992f7c0f2

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2026-03-04

Date Updated: 2026-04-21

Author: Abinaya

...
...

HPE has published an advisory for CVE-2026-23600, an authentication-bypass vulnerability in AutoPass License Server (APLS) prior to 9.19 that can be exploited remotely without privileges or user interaction (CVSS 7.3). HPE recommends upgrading to a fixed release and temporary mitigations such as restricting network exposure to trusted admin subnets/VPNs, auditing admin access, monitoring for suspicious activity, and applying host OS patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.