Description
A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could allow a remote low-privileged authenticated user to achieve administrative privilege on the web-management interface leading to complete system compromise.
Published: 2026-09-15
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

A flaw in the API of HPE EdgeConnect SD-WAN Gateways allows a remote user with only basic authentication rights to bypass normal authorization checks and gain administrative control over the web‑management interface. This privilege escalation can give the attacker full system compromise, enabling modification of network policies, extraction of sensitive data, and potential further lateral movement within the enterprise network.

Affected Systems

The affected product is Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific firmware or hardware revision numbers are disclosed in this advisory, so the issue applies to all versions deployed in the field until a vendor‑issued fix is applied.

Risk and Exploitability

The CVSS score of 8.8 indicates a high‑severity vulnerability, while the EPSS score is not available. The fact that the vulnerability is not yet listed in CISA’s KEV catalog suggests that a widespread, publicly available exploit has not yet been reported, however the impact remains severe. Successful exploitation requires the attacker to be authenticated to the API, but the attack can be executed remotely from outside the host network, making it a realistic risk in many environments.

Generated by OpenCVE AI on September 15, 2026 at 22:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by HPE that fixes the authorization control in the EdgeConnect API.
  • Configure firewall rules or network segmentation to limit API access to trusted internal IP ranges only.
  • Rotate or enforce strong, unique passwords for all API and web‑management accounts, and enable multi‑factor authentication if supported.

Generated by OpenCVE AI on September 15, 2026 at 22:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could allow a remote low-privileged authenticated user to achieve administrative privilege on the web-management interface leading to complete system compromise.
Title Authorization Bypass Leading to Privilege Escalation in HPE Networking EdgeConnect SD-WAN Gateways
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:23:37.869Z

Reserved: 2026-08-19T16:11:18.067Z

Link: CVE-2026-76677

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-15T20:17:49.540

Modified: 2026-09-15T20:17:49.540

Link: CVE-2026-76677

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:00:16Z

Weaknesses