Vulnerabilities & Exploits

HPE iMC authentication bypass exposes management data

INCIBE-CERT says HPE Intelligent Management Center (iMC) has a critical authentication bypass, tracked as CVE-2026-79842, in versions before 7.3 E0713. The flaw lets a remote unauthenticated attacker reach restricted functions through the management interface.

In plain terms, the login check can be skipped, so someone who can talk to iMC may be able to read or change sensitive information without valid credentials. Because iMC is the admin plane for centralized infrastructure management, account-based controls do not contain the exposure once the bypass is possible.

That puts the management layer itself on the risk map: if iMC sits in front of devices, config, or operator data, a successful bypass can undercut the trust operators place in it even before any downstream systems are touched.

2 sources · 6h ago

CVE-2026-79842

NVD KEV

CVSS 9.1 CRITICAL: an authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713

Timeline

Sources

Part of the PlainSec briefing for 2026-10-09

Every edition of this story: HPE iMC authentication bypass exposes management data

More from today