Description
Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level.
Published: 2026-09-15
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Information Disclosure via Server‑Side Request Forgery
Action: Apply Patch
AI Analysis

Impact

Vulnerabilities in the EdgeConnect SD‑WAN Orchestrator API enable a remote attacker who is authenticated with low‑privilege credentials to perform server‑side request forgery (SSRF). A successful exploit permits enumeration of internal host structures and disclosure of data beyond what the user’s role normally authorizes, compromising confidentiality and potentially revealing sensitive network topology or configuration details.

Affected Systems

The affected product is Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific version information is provided in the advisory, so all current releases may be impacted until a vendor‑issued update becomes available.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity flaw. EPSS is not available, and the vulnerability is not listed in CISA KEV, suggesting no widespread, documented exploitation at this time. Exploitation requires authenticated access with low‑privilege rights, so attackers must first compromise an account or reuse legitimate credentials. Once access is achieved, the SSRF can reach internal services and expose data that should not be exposed to those credentials.

Generated by OpenCVE AI on September 15, 2026 at 22:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE EdgeConnect SD‑WAN Orchestrator patch or update when it becomes available
  • Restrict API access to authorized roles only, removing or disabling low‑privilege accounts that are not needed for the attack surface
  • Monitor API traffic for abnormal request patterns and enforce network segmentation to block internal service endpoints from public API endpoints

Generated by OpenCVE AI on September 15, 2026 at 22:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level.
Title Authenticated Server-Side Request Forgery Vulnerabilities Leading to Information Disclosure in EdgeConnect SD-WAN Orchestrator
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:23:40.162Z

Reserved: 2026-08-19T16:11:18.067Z

Link: CVE-2026-76680

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-15T20:17:49.890

Modified: 2026-09-15T20:17:49.890

Link: CVE-2026-76680

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:00:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)