CriticalCritical vulnerability
CVE-2026-79794 (CVSS 9.1)
NVD · officialPublished Oct 6, 2026Risk 50/100
A SQL injection vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.
Technical details
CVSS
9.1
AV:NetworkAC:LowPR:HighUI:NoneC:HighI:HighA:High
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source