Description
A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.
Published: 2026-09-15
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: Sensitive Information Disclosure
Action: Patch Immediately
AI Analysis

Impact

A vulnerability in the HPE EdgeConnect SD‑WAN Orchestrator allows an authenticated remote attacker with read‑only privileges to send a specially crafted request to the cache synchronization endpoint. This can expose sensitive third‑party API tokens and credentials, creating a path for lateral movement to external security platforms. The weakness results in the disclosure of confidential configuration and credential data, which can be leveraged for further compromise.

Affected Systems

The affected product is Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. The specific versions impacted are not listed in the data, so all current releases of the SD‑WAN Orchestrator are presumed at risk until an official fix is provided.

Risk and Exploitability

The CVSS score of 9.9 indicates a critical severity, while the EPSS score is not available; the lack of a CISA KEV listing does not mean the flaw is unexploitable. The attack vector is remote, requiring only authenticated access with read‑only rights, which are granted to many users by default. Once hijacked, an attacker can retrieve sensitive tokens that could be used to compromise other network infrastructure or external services. The threat is therefore high, especially in environments where read‑only accounts are widely used or where sensitive tokens are stored in configuration files.

Generated by OpenCVE AI on September 15, 2026 at 22:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE patch for EdgeConnect SD‑WAN Orchestrator that removes the cache synchronization endpoint vulnerability
  • Disable or restrict access to the cache synchronization endpoint until a patch is applied, ensuring that only authorized, privileged users can call it
  • Configure network segmentation and monitor for anomalous API traffic to guard against lateral movement attempts

Generated by OpenCVE AI on September 15, 2026 at 22:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.
Title Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Orchestrator
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:23:33.951Z

Reserved: 2026-08-19T16:11:04.542Z

Link: CVE-2026-76672

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-15T20:17:48.977

Modified: 2026-09-15T20:17:48.977

Link: CVE-2026-76672

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:00:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor