CVE-2026-76709

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
22/09/2026
Last modified:
28/09/2026

Description

A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain unauthorized write access to the file system with elevated privileges, potentially resulting in full system compromise.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:arubanetworks:analytics_and_location_engine:*:*:*:*:*:*:*:* 5.1.0.0 (excluding)