Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-76709

Gravedad CVSS v3.1:
CRÍTICA
Tipo:
CWE-284 Control de acceso incorrecto
Fecha de publicación:
22/09/2026
Última modificación:
28/09/2026

Descripción

*** Pendiente de traducción *** A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain unauthorized write access to the file system with elevated privileges, potentially resulting in full system compromise.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:arubanetworks:analytics_and_location_engine:*:*:*:*:*:*:*:* 5.1.0.0 (excluyendo)