Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-76717— Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (ALE)

Quick assessment

Affected
Hewlett Packard Enterprise (HPE) ALE
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input to a specific API endpoin

CVSS 5.3 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
Hewlett Packard Enterprise (HPE) ALE 0.0.0.0≤ 5.0.0.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-76717

Vulnerability Information

Shenlong is analyzing...


Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (ALE)
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input to a specific API endpoint. Successful exploitation could result in the disclosure of sensitive user information, including password hashes, which could be used to facilitate further attacks.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Hewlett Packard Enterprise (HPE) ALE 0.0.0.0 ~ 5.0.0.0 -

II. Public POCs for CVE-2026-76717

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-76717

登录查看更多情报信息。

Other References for CVE-2026-76717 (1)

Same Patch Batch · Hewlett Packard Enterprise (HPE) · 2026-09-22 · 10 CVEs total

CVE-2026-76708 9.8 CRITICAL Unauthenticated Remote Unauthorized Access Vulnerability in HPE Networking Analytics and L
CVE-2026-76709 9.8 CRITICAL Unauthenticated Remote Arbitrary File Write Vulnerability in HPE Networking Analytics and
CVE-2026-76711 7.5 HIGH Unauthenticated Remote Data Injection Vulnerability in HPE Networking Analytics and Locati
CVE-2026-76710 7.5 HIGH Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking An
CVE-2026-76712 7.3 HIGH Unauthenticated Remote Unauthorized Access, Information Disclosure, and Denial of Service
CVE-2026-76713 7.2 HIGH Authenticated Remote File System Access Vulnerability in HPE Networking Analytics and Loca
CVE-2026-76714 7.2 HIGH Authenticated Remote Code Execution with Elevated Privileges Vulnerability in HPE Networki
CVE-2026-76715 7.1 HIGH Unauthenticated Man-in-the-Middle Attach Leads to Remote Code Execution Vulnerability in H
CVE-2026-76716 5.3 MEDIUM Unauthenticated Remote Unauthorized Access and Denial of Service Vulnerabilities in HPE Ne

IV. Related Vulnerabilities

V. Comments for CVE-2026-76717

No comments yet


Leave a comment