PT-2026-22593 · Hewlett Packard · Hpe Autopass License Server

CVE-2026-23600

·

Published

2026-03-02

·

Updated

2026-08-10

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions HPE AutoPass License Server versions prior to 9.19
Description A remote authentication bypass exists in the HPE AutoPass License Server (APLS). This flaw allows remote attackers to bypass authentication mechanisms and gain unauthorized access to protected licensing functions if the service is exposed to untrusted networks.
Recommendations Upgrade to APLS version 9.19 or later. Restrict access to the license server to trusted administrator networks or VPNs to minimize external exposure.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-23600
ZDI-26-134

Affected Products

Hpe Autopass License Server