Description
A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.
Published: 2026-09-15
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Patch Immediately
AI Analysis

Impact

The disclosed vulnerability in the HPE EdgeConnect SD‑WAN Orchestrator allows an attacker who has authenticated, read‑only access to the system to trigger a specially crafted request against the cache synchronization endpoint. By doing so the attacker can retrieve sensitive third‑party API tokens and credentials that are stored within the Orchestrator’s configuration. Because these credentials enable communication with external security platforms, the compromise could be used to launch lateral movement or further attacks against the wider network. The weakness is a form of sensitive data exposure resulting from inadequate access‑control checks on the cache endpoint, corresponding to CWE‑200.

Affected Systems

The affected product is Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways, specifically the SD‑WAN Orchestrator component. No specific version numbers are disclosed in the advisory, so all current releases of the orchestrator should be considered vulnerable until a vendor patch is applied.

Risk and Exploitability

The CVSS score of 9.9 signifies critical severity, yet the EPSS score is less than 1%, indicating a low probability of exploitation at this time. The flaw is not listed in the CISA KEV catalog. The attack vector is remote and requires authenticated access with limited read‑only rights – credentials that are not uncommon in managed environments. Should an attacker acquire such credentials, the ability to pull sensitive API tokens creates a high‑impact foothold for subsequent compromise. Consequently, the threat is high, especially in environments where read‑only accounts are broadly granted or where the orchestrator interfaces with external platforms.

Generated by OpenCVE AI on September 20, 2026 at 12:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor‑supplied patch or update for the EdgeConnect SD‑WAN Orchestrator that removes or secures the cache synchronization endpoint.
  • If a patch is not immediately available, restrict or disable direct access to the cache synchronization endpoint, ensuring that only privileged administrators can invoke it.
  • Enforce strict network segmentation around the SD‑WAN Orchestrator and monitor traffic looking for anomalous API calls that could signal lateral movement attempts.

Generated by OpenCVE AI on September 20, 2026 at 12:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System
CPEs cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.7.0:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:9.7.0.0:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways

Thu, 17 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 15 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.
Title Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Orchestrator
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

Arubanetworks Edgeconnect Sd-wan Orchestrator
Hewlett Packard Enterprise (hpe) Edgeconnect Sd-wan Gateways
Hpe Edgeconnect Operating System
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-20T00:39:36.236Z

Reserved: 2026-08-19T16:11:04.542Z

Link: CVE-2026-76672

cve-icon Vulnrichment

Updated: 2026-09-20T00:39:20.667Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:17:48.977

Modified: 2026-09-25T12:55:44.320

Link: CVE-2026-76672

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T13:00:11Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor