Database/Control plane, storage & DevOps

HPE Performance Cluster Manager (HPCM) GUI authentication bypass: Authentication bypass in the HPCM web GUI
CVE-2025-27086Control plane, storage & DevOpscurated
Impact
Authentication bypass in the HPCM web GUI. HPCM provisions and manages HPC/AI cluster nodes, so bypassing its authentication gives an attacker the ability to reimage and reconfigure compute nodes at will.
Who can reach it
Unauthenticated network access to the HPCM GUI. High attack complexity.
What to do
Apply the HPCM update per HPESBCR04842. Management-server upgrade. Keep HPCM on an isolated provisioning network - it has PXE/imaging authority over the whole cluster.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.