Database/Control plane, storage & DevOps

HPE Performance Cluster Manager (HPCM) GUI authentication bypass: Authentication bypass in the HPCM web GUI
CVSS 8.1CVE-2025-27086Control plane, storage & DevOpscurated
Impact
Authentication bypass in the HPCM web GUI. HPCM provisions and manages HPC/AI cluster nodes, so bypassing its authentication gives an attacker the ability to reimage and reconfigure compute nodes at will.
Who can reach it
Unauthenticated network access to the HPCM GUI. High attack complexity.
What to do
Apply the HPCM update per HPESBCR04842. Management-server upgrade. Keep HPCM on an isolated provisioning network - it has PXE/imaging authority over the whole cluster.
References
Related entries
- HTCondor (IDToken authorization restrictions): The per-token authorization restrictions attached withCVE-2025-30093 · HTCondor (IDToken authorization restrictions)High
- ConnectWise ScreenConnect: ViewState code injectionCVE-2025-3935 · ConnectWise ScreenConnectHigh
- MinIO (service accounts / STS session policies): The session policy attached to a service account or STS credential isCVE-2025-62506 · MinIO (service accounts / STS session policies)High
- Apache CloudStack: MinIO policies survive bucket deletion, giving a former owner access to a new bucket of the same nameCVE-2025-66467 · Apache CloudStack (MinIO object store policy cleanup on bucket deletion)High
- N-able N-central: Incomplete patch for CVE-2026-18556CVE-2026-18577 · N-able N-centralHigh
- VMware Aria Operations (command injection during assisted migration): An unauthenticated attacker injects commandsCVE-2026-22719 · VMware Aria Operations (command injection during assisted migration)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.