Hewlett Packard Enterprise (HPE) AutoPass License Server (APLS) was disclosed to contain a remote authentication bypass vulnerability tracked as CVE-2026-23600 (ZDI-CAN-27634) with a CVSS 7.3 rating. The flaw is in the product’s web service (default TCP port 5814) and stems from incorrect authentication checks before granting access to functionality, allowing unauthenticated remote attackers to bypass login controls and access protected capabilities.
HPE issued an update to remediate the issue (security bulletin HPESBGN05003), and the Canadian Centre for Cyber Security highlighted that APLS versions prior to 9.19 are affected and urged administrators to apply the vendor-provided fixes. The Zero Day Initiative advisory notes the vulnerability was reported to HPE in September 2025 and publicly released via coordinated disclosure in March 2026, with credit attributed to an anonymous reporter.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-04, a GitHub pull request was opened in the projectdiscovery/nuclei-templates repository to add a Nuclei template for detecting exposed HPE AutoPass License Server panels associated with CVE-2026-23600. The submission was reviewed and flagged for syntax, regex, metadata, and false-positive issues, indicating early community detection work around the vulnerability.
On 2026-03-03, the Zero Day Initiative released advisory ZDI-26-134 for CVE-2026-23600, describing an authentication bypass in the APLS web service on TCP port 5814 caused by improper authentication checks. ZDI said exploitation requires no prior authentication and noted that HPE had already released an update to remediate the flaw.
On 2026-02-27, HPE published security bulletin HPESBGN05003 rev.1 for a remote authentication bypass vulnerability in HPE AutoPass License Server, tracked as CVE-2026-23600. The issue affects APLS versions prior to 9.19, and HPE advised customers to upgrade to a fixed release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcegithub.com
Open sourcezerodayinitiative.com
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.