CVE-2026-23600Disclosure(hpe / autopass_license_server)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch hpe autopass_license_server systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • autopass_license_server

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 13 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 10 signals
  • Disclosure: 6 classified signals
  • Peaked 6d ago at 3 mentions (2026-03-03); latest day: 1
  • 13 total mentions across 8 days

Affected systems

Vendors
Products
autopass_license_server

Deep dive

Activity timeline13 mentions / 8d
01223Mentions · 2026-03-02: 2Mentions · 2026-03-03: 3Mentions · 2026-03-04: 3Mentions · 2026-03-05: 1Mentions · 2026-03-08: 1Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-16: 1Active Exploitation · 2026-03-16: 1Patch / Workaround · 2026-03-03: 3Patch / Workaround · 2026-03-04: 3Technical Details · 2026-03-02: 1Technical Details · 2026-03-03: 3Technical Details · 2026-03-04: 3Technical Details · 2026-03-05: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-10: 103-0203-0303-0403-0503-0803-1003-1103-16
Signal classification3 categories
Disclosure
646.2%
Patch
646.2%
Active Exploitation
17.7%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-03-022
Disclosure2
2026-03-033
Patch3
2026-03-043
Patch3
2026-03-051
Disclosure1
2026-03-081
Disclosure1
2026-03-101
Disclosure1
2026-03-111
Disclosure1
2026-03-161
Active Exploitation1
Full discourse13 posts
  • Gray Hats@the_yellow_fall
    Patch

    HPE warns of a critical CVSS 10.0 vulnerability (CVE-2026-23600) in AutoPass License Server. Remote attackers can bypass authentication. Patch to 9.19 now! #HPE #CyberSecurity #InfoSec #CVE202623600 #DataBreach #TechAlert #EnterpriseSecurity https://securityonline.info/urgent-patch-required-hpe-autopass-license-server-hits-maximum-severity-risk/

    Post summary

    HPE has issued a critical patch for CVE-2026-23600, a CVSS 10.0 authentication bypass vulnerability in AutoPass License Server, and urges users to update to version 9.19.

    00002267
    10.5K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    HPE APLS の脆弱性 CVE-2026-23600 が FIX:ネットワーク経由でログイン制御を回避 https://iototsecnews.jp/2026/03/03/hpe-autopass-vulnerability-allows-remote-attackers-to-bypass-authentication/ HPE のライセンス管理システム AutoPass License Server (APLS) に、リモートからの認証バイパスを許してしまう深刻な脆弱性 CVE-2026-23600 が発見されました。この問題の原因は、APLS のログイン制御ロジックに不備があり、本来であれば正規の ID とパスワードが必要な保護機能に対して、未認証のリモート攻撃者が直接アクセスする可能性が生じています。 この脆弱性は、攻撃の複雑さが低いと評価されており、特別な権限やユーザーの操作を必要とせずに悪用が可能なものです。この不備を突く攻撃者は、ライセンス管理権限を不正に取得する恐れがあり、企業のソフトウェア資産やインフラの運用に支障をきたすというリスクが生じます。ご利用のチームは、ご注意ください。 #AutoPassLicenseServer #CVE202623600 #HPE #Vulnerability

    Post summary

    The post announces the discovery of CVE‑2026‑23600 in HPE AutoPass License Server, detailing a remote authentication bypass, but provides no proof‑of‑concept, exploit, patch, or indication of active exploitation.

    01000154
    484 followersView on X
  • ThreatCluster@threatcluster
    Patch

    HPE AutoPass License Server flaw CVE-2026-23600 enables remote authentication bypass, according to Trend Micro ZDI. HPE warns APLS users and provides updated software. #Vulnerability https://threatcluster.io/cluster/hpe-autopass-vulnerability-enables-remote-authentication-byp-7fa65129

    Post summary

    HPE AutoPass License Server flaw CVE-2026-23600 allows remote authentication bypass; HPE has issued an update to mitigate the issue.

    1000050
    86 followersView on X
  • e2u-it@ItE2u
    Active Exploitation

    HPE AutoPass: Auth-Bypass-Schwachstelle wird ausgenutzt https://www.security-insider.de:443/hpe-autopass-license-server-authentifizierung-bypass-cve-2026-23600-a-f479f0857765383cff384e39319e30e9/

    Post summary

    The article headline indicates that the HPE AutoPass authorization bypass (CVE‑2026‑23600) is actively being exploited, but no additional exploit details or mitigation guidance are provided.

    0000046
    19 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos HPE ❗ CVE-2026-23600 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-hpe-5/ https://t.co/gAbrXQJsQo

    Post summary

    The tweet alerts to an HPE product vulnerability (CVE-2026-23600) and provides links for additional information, but lacks any technical details, PoC, exploit, or patch information.

    0000086
    6.6K followersView on X
  • UNDERCODE NEWS@UndercodeNews
    Disclosure

    🚨 Critical Authentication Bypass Discovered in HPE AutoPass License Server (#CVE-2026-23600) -Fact Checker: ✅: 3 ❌: 0 || 3/3 http://undercodenews.com/critical-authentication-bypass-discovered-in-hpe-autopass-license-server-cve-2026-23600/

    Post summary

    The tweet announces the discovery of a critical authentication bypass (CVE-2026-23600) in HPE AutoPass License Server and links to a news article for details, without referencing proof of concept, exploit, or mitigation information.

    0000059
    667 followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Hewlett Packard Enterprise AutoPass License Server Authentication Bypass Vulnerability (CVE-2026-23600) #AuthenticationBypassVulnerability #CVE202623600 #CyberSecurity #HewlettPackard https://www.systemtek.co.uk/?p=48627 https://t.co/FdbY2QrfNT

    Post summary

    The tweet announces the discovery of a new authentication bypass vulnerability, CVE-2026-23600, affecting the Hewlett Packard Enterprise AutoPass License Server.

    0000047
    1.8K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 HPE AutoPass License Server Flaw (CVE-2026-23600) Enables Remote Authentication Bypass A network-exploitable vulnerability in HPE AutoPass License Server (APLS) (CVE-2026-23600, CVSS 7.3) allows remote attackers to bypass authentication and access protected licensing functions if the service is exposed to untrusted networks. HPE says upgrading to APLS 9.19+ and restricting access to trusted admin networks/VPNs mitigates the risk. 🎯 Target: Global/Enterprise (License Server Infrastructure) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/hpe-autopass-vulnerability/

    Post summary

    The post announces a remote authentication bypass flaw in HPE AutoPass License Server (CVE‑2026‑23600) and recommends upgrading to version 9.19+ and limiting network exposure as a mitigation.

    0000039
    262 followersView on X
  • kantan.news@KantanNewsX
    Patch

    HPE AutoPass kullanan kurumlar için kritik uyarı! Saldırganların şifre girmeden sisteme erişmesine olanak tanıyan güvenlik açığı (CVE-2026-23600) tespit edildi. Sistemlerinizi acilen 9.19 sürümüne güncelleyin. Haberin detayı: https://kantan.news/x_article.php?slug=hpe-autopass-lisans-sunucusunda-kritik-kimlik-dorulama-riski

    Post summary

    A critical authentication bypass vulnerability (CVE‑2026‑23600) affecting HPE AutoPass has been identified; users are urged to update to version 9.19 to mitigate the risk.

    0000089
    896 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Critical HPE AutoPass License Server Flaw Lets Attackers Bypass Authentication Remotely (CVE-2026-23600) HPE disclosed CVE-2026-23600 (CVSS 7.3) in AutoPass License Server (APLS) that allows unauthenticated remote access to protected functions over the network in versions prior to 9.19. Organizations should upgrade to APLS 9.19+ and restrict external exposure of license servers to reduce easy pre-auth compromise. 🎯 Target: Global/Enterprises using HPE AutoPass License Server #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/hpe-autopass-vulnerability/

    Post summary

    HPE disclosed CVE-2026-23600, a CVSS 7.3 unauthenticated remote‑access flaw in AutoPass License Server versions before 9.19, and recommends upgrading to 9.19+ and limiting external exposure.

    0000043
    262 followersView on X
  • しーにゃ♪@公式@Syynya
    Patch

    【セキュリティ ニュース】HPEのライセンス管理製品に認証回避の脆弱性 - 修正版が公開:Security NEXT https://www.security-next.com/181620 『現地時間2026年2月27日にアドバイザリを公開し、リモートから認証をバイパスできる脆弱性「CVE-2026-23600」について明らかにしたもの』 ゔ―む。

    Post summary

    An advisory for HPE's license management product reports an authentication bypass flaw (CVE-2026-23600) and indicates a patch has been released.

    0000045
    957 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23600 Remote Authentication Bypass Vulnerability in HPE AutoPass License Server https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23600

    Post summary

    The text announces a remote authentication bypass vulnerability in HPE AutoPass License Server, but provides no further details such as PoC, exploit, patch, or active exploitation.

    0000054
    4.0K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in HPE AutoPass License Server (CVE-2026-23600) https://vuldb.com/?id.348371

    Post summary

    A new critical vulnerability (CVE-2026-23600) has been identified in HPE AutoPass License Server, with a reference link to vuldb.com for further details.

    0000083
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphpeautopass_license_server---

Explore more