Description
Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level.
Published: 2026-09-15
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via Server‑Side Request Forgery
Action: Apply Patch
AI Analysis

Impact

The EdgeConnect SD‑WAN Orchestrator contains server‑side request forgery weaknesses in its API that allow a user with low‑privilege authentication to craft requests to internal services. If an attacker can log in or reuse stolen credentials, the vulnerability can be used to enumerate host structures and expose sensitive configuration or topology data that falls far beyond the scope of the user’s authorized role.

Affected Systems

Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways are affected. The advisory does not specify a version range, so all current releases may be vulnerable until a vendor solution is released.

Risk and Exploitability

The CVSS score of 8.5 reflects a high severity flaw, while the EPSS score of less than 1% and absence from the CISA KEV catalog suggest that widespread exploitation has not been observed yet. An attacker must first obtain or reuse low-privilege credentials to access the API, but once authenticated, the SSRF can reach internal endpoints and recover sensitive data, creating a high-risk confidentiality breach.

Generated by OpenCVE AI on September 20, 2026 at 12:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest HPE EdgeConnect SD‑WAN Orchestrator update as soon as it is available
  • Restrict API access so that only roles with necessary privileges can use the vulnerable endpoints
  • Segregate internal service endpoints from the network path used by the API or block internal hosts from the public interface

Generated by OpenCVE AI on September 20, 2026 at 12:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System
CPEs cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.7.0:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:9.7.0.0:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways

Thu, 17 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Tue, 15 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level.
Title Authenticated Server-Side Request Forgery Vulnerabilities Leading to Information Disclosure in EdgeConnect SD-WAN Orchestrator
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Arubanetworks Edgeconnect Sd-wan Orchestrator
Hewlett Packard Enterprise (hpe) Edgeconnect Sd-wan Gateways
Hpe Edgeconnect Operating System
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-21T19:47:25.803Z

Reserved: 2026-08-19T16:11:18.067Z

Link: CVE-2026-76680

cve-icon Vulnrichment

Updated: 2026-09-21T19:47:20.815Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:17:49.890

Modified: 2026-09-25T12:56:56.180

Link: CVE-2026-76680

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T12:30:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)