Skip to content
TrustList
News

HPE iMC authentication bypass (CVSS 9.1) is fixed in 7.3 E0713

Editorial

By TrustList Editorial

The flaw needs no credentials or user action and every iMC build before 7.3 E0713 is affected. HPE published the bulletin on 8 October and updated it on 9 October.

About HPE iMC authentication bypass (CVSS 9.1) is fixed in 7.3 E0713

HPE iMC authentication bypass (CVSS 9.1) is fixed in 7.3 E0713

8 October 2026: Hewlett Packard Enterprise has fixed CVE-2026-79842, an authentication bypass in HPE Intelligent Management Center (iMC) that scores 9.1 on the CVSS 3.1 scale. Every iMC build before version 7.3 E0713 is affected, and the fix is to upgrade to that release.

Not yet independently verified. HPE's bulletin does not say whether the flaw has been exploited; the report that no attacks are known comes from a security news site only. We will update this when it can be confirmed, and remove this note.

HPE's bulletin, HPESBNW05157, says the flaw can be exploited remotely. An attacker needs no credentials and no action from a user, which is what pushes the score into the critical band. The weakness is classed as missing authorisation (CWE-862). HPE credits the researcher Nhi Nguyen. The bulletin says nothing about exploitation; SecurityOnline reports that HPE knows of no attacks and no public proof-of-concept.

iMC is the management console many network teams use to configure, monitor and back up switches, routers and wireless gear. A bypass in that console is serious for a reason beyond the bug itself: the console holds device credentials and can push configuration to everything it manages. An attacker who reaches it is no longer attacking one server but the network behind it.

The practical steps are short. Find every iMC server, including the ones set up years ago for a branch or a lab, and read the version from the console. Upgrade to 7.3 E0713 through the HPE Aruba support portal. Until the upgrade is done, keep the console off any network a user or an internet-facing system can reach, and limit access to a dedicated management segment. Security reports on the bulletin make the same recommendation.

HPE published the bulletin on 8 October 2026, one of a set that day that also covered a separate iLO 7 flaw, CVE-2026-79820, fixed in a different release. The two are unrelated, so patching iMC does not clear the iLO issue.

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy