CVE-2026-76708

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
22/09/2026
Last modified:
25/09/2026

Description

A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and system accounts. An unauthenticated remote attacker could exploit this vulnerability by attempting to log in using these known default credentials.<br /> <br /> Successful exploitation could result in an attacker gaining unauthorized access to the application&amp;#39;s management interface and the underlying operating system, potentially leading to full system compromise.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:arubanetworks:analytics_and_location_engine:*:*:*:*:*:*:*:* 5.1.0.0 (excluding)