CVE-2026-76715

Severity CVSS v4.0:
Pending analysis
Type:
CWE-300 Channel Accessible by Non-Endpoint
Publication date:
22/09/2026
Last modified:
28/09/2026

Description

A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-middle (MitM) attack. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the affected appliance.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:arubanetworks:analytics_and_location_engine:*:*:*:*:*:*:*:* 5.1.0.0 (excluding)