CVE-2026-76708
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
22/09/2026
Last modified:
25/09/2026
Description
A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and system accounts. An unauthenticated remote attacker could exploit this vulnerability by attempting to log in using these known default credentials.<br />
<br />
Successful exploitation could result in an attacker gaining unauthorized access to the application&#39;s management interface and the underlying operating system, potentially leading to full system compromise.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:arubanetworks:analytics_and_location_engine:*:*:*:*:*:*:*:* | 5.1.0.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page


