Vulnerability
Published 2026-09-22
Verified 2026-09-27

HPE Networking ALE CVE-2026-76708 / CVE-2026-76709 (CVSS 9.8): unauth hard-coded creds + arbitrary file write — fix 5.1.0.0 (HPESBNW05137)

Hewlett Packard Enterprise advisory HPESBNW05137 (rev.1, 22 September 2026) covers multiple flaws in HPE Networking Analytics and Location Engine (ALE) ≤ 5.0.0.0, fixed in ALE 5.1.0.0. Lead criticals: CVE-2026-76708 (CVSS 9.8) — default hard-coded credentials on administrative/system accounts enabling unauthenticated remote login to the ALE management interface and underlying OS (CWE-798); CVE-2026-76709 (CVSS 9.8) — unauthenticated remote arbitrary file write with elevated privileges via an internal administrative component. Additional highs include info disclosure, data injection, auth’d root filesystem/command execution, MitM RCE, and API password-hash disclosure (CVE-2026-76710 through CVE-2026-76717). HPE stated no known public exploit code or active exploitation at advisory time. Primary: HPE HPESBNW05137; secondary: CVE.report / Tenable CVE pages; wire: Cyber Security News 25 Sep.

Product
HPE Networking Analytics and Location Engine (ALE)
Versions
Affected: ALE 5.0.0.0 and earlier (0.0.0.0–5.0.0.0 per CNA). Fixed: ALE 5.1.0.0. Unsupported older lines treat as potentially affected.
CVSS
Exploited in Australia?
unknown
Patch to
Upgrade ALE to 5.1.0.0. Until patched: restrict CLI/web management to a dedicated L2 segment/VLAN, enforce L3 firewalls to trusted management hosts, enable logging/accounting. Change any default credentials if still present on interim builds.

Primary: HPE — HPESBNW05137 (ALE security bulletin) · Vendor: Hewlett Packard Enterprise (vendor advisory) · CVE: CVE-2026-76708, CVE-2026-76709, CVE-2026-76710, CVE-2026-76717 · CVE.report — CVE-2026-76708 (hard-coded credentials)

vulnerabilities network cloud