GPU VulnDB

Database/Control plane, storage & DevOps

HPE Performance Cluster Manager (HPCM) GUI authentication bypass: Authentication bypass in the HPCM web GUI

CVE-2025-27086Control plane, storage & DevOpscurated

Impact

Authentication bypass in the HPCM web GUI. HPCM provisions and manages HPC/AI cluster nodes, so bypassing its authentication gives an attacker the ability to reimage and reconfigure compute nodes at will.

Who can reach it

Unauthenticated network access to the HPCM GUI. High attack complexity.

What to do

Apply the HPCM update per HPESBCR04842. Management-server upgrade. Keep HPCM on an isolated provisioning network - it has PXE/imaging authority over the whole cluster.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.