CVE-2026-79842
CVSS 9.1 CRITICAL: an authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713
Vulnerabilities & Exploits
INCIBE-CERT says HPE Intelligent Management Center (iMC) has a critical authentication bypass, tracked as CVE-2026-79842, in versions before 7.3 E0713. The flaw lets a remote unauthenticated attacker reach restricted functions through the management interface.
In plain terms, the login check can be skipped, so someone who can talk to iMC may be able to read or change sensitive information without valid credentials. Because iMC is the admin plane for centralized infrastructure management, account-based controls do not contain the exposure once the bypass is possible.
That puts the management layer itself on the risk map: if iMC sits in front of devices, config, or operator data, a successful bypass can undercut the trust operators place in it even before any downstream systems are touched.
2 sources · 6h ago
CVSS 9.1 CRITICAL: an authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713
CSIRT Italia / ACN
Risolta una nuova vulnerabilità in HPE Intelligent Management Center
Rilasciati aggiornamenti di sicurezza per risolvere una vulnerabilità con gravità "critica" in HPE Intelligent Management Center (iMC).
originalINCIBE-CERT
Omisión de autenticación en Intelligent Management Center de HPE
HPE ha publicado una vulnerabilidad de severidad crítica que, en caso de ser explotada, podría permiti
originalPart of the PlainSec briefing for 2026-10-09
Every edition of this story: HPE iMC authentication bypass exposes management data