HPE iMC authentication bypass (CVSS 9.1) is fixed in 7.3 E0713
EditorialBy TrustList Editorial
The flaw needs no credentials or user action and every iMC build before 7.3 E0713 is affected. HPE published the bulletin on 8 October and updated it on 9 October.
About HPE iMC authentication bypass (CVSS 9.1) is fixed in 7.3 E0713
HPE iMC authentication bypass (CVSS 9.1) is fixed in 7.3 E0713
8 October 2026: Hewlett Packard Enterprise has fixed CVE-2026-79842, an authentication bypass in HPE Intelligent Management Center (iMC) that scores 9.1 on the CVSS 3.1 scale. Every iMC build before version 7.3 E0713 is affected, and the fix is to upgrade to that release.
Not yet independently verified. HPE's bulletin does not say whether the flaw has been exploited; the report that no attacks are known comes from a security news site only. We will update this when it can be confirmed, and remove this note.
HPE's bulletin, HPESBNW05157, says the flaw can be exploited remotely. An attacker needs no credentials and no action from a user, which is what pushes the score into the critical band. The weakness is classed as missing authorisation (CWE-862). HPE credits the researcher Nhi Nguyen. The bulletin says nothing about exploitation; SecurityOnline reports that HPE knows of no attacks and no public proof-of-concept.
iMC is the management console many network teams use to configure, monitor and back up switches, routers and wireless gear. A bypass in that console is serious for a reason beyond the bug itself: the console holds device credentials and can push configuration to everything it manages. An attacker who reaches it is no longer attacking one server but the network behind it.
The practical steps are short. Find every iMC server, including the ones set up years ago for a branch or a lab, and read the version from the console. Upgrade to 7.3 E0713 through the HPE Aruba support portal. Until the upgrade is done, keep the console off any network a user or an internet-facing system can reach, and limit access to a dedicated management segment. Security reports on the bulletin make the same recommendation.
HPE published the bulletin on 8 October 2026, one of a set that day that also covered a separate iLO 7 flaw, CVE-2026-79820, fixed in a different release. The two are unrelated, so patching iMC does not clear the iLO issue.
Sources
Categories & features
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.