Description
A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privileges to access sensitive information beyond what is authorized by the user's existing privilege level. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by EdgeConnect SD-WAN Orchestrator.
Published: 2026-09-15
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Apply Patch
AI Analysis

Impact

A vulnerability in the EdgeConnect SD‑WAN Orchestrator API permits an authenticated attacker with low privileges to access sensitive information beyond the authorized scope of their account. Successful exploitation could expose data that might enable further compromise of network services managed by the Orchestrator. The flaw results from insufficient authorization checks, leading to an information disclosure vulnerability.

Affected Systems

The affected product is Hewlett Packard Enterprise's EdgeConnect SD‑WAN Gateways. No version range is specified in the advisory, so all releases of the Orchestrator API should be reviewed until vendor confirms the fix.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity impact. The EPSS score is < 1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack requires valid API credentials, but an authenticated user with even low‑level privileges can abuse the flaw. Remote attackers can retrieve confidential data over the network, and the disclosed information could form a stepping‑stone for further lateral movement or privilege escalation within the organization.

Generated by OpenCVE AI on September 20, 2026 at 12:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade HPE EdgeConnect SD‑WAN Orchestrator to a version that contains the fix or core security patch.
  • Limit API access by configuring firewall or VPN restrictions so only trusted management servers can reach the API endpoint.
  • Enforce least‑privilege for all API accounts and regularly review permissions; disable or remove accounts with unnecessary access.

Generated by OpenCVE AI on September 20, 2026 at 12:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System
CPEs cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.7.0:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:9.7.0.0:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privileges to access sensitive information beyond what is authorized by the user's existing privilege level. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by EdgeConnect SD-WAN Orchestrator.
Title Authenticated Information Disclosure Vulnerability in HPE Networking EdgeConnect SD-WAN Orchestrator API
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Arubanetworks Edgeconnect Sd-wan Orchestrator
Hewlett Packard Enterprise (hpe) Edgeconnect Sd-wan Gateways
Hpe Edgeconnect Operating System
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-21T19:55:25.113Z

Reserved: 2026-08-19T16:11:18.067Z

Link: CVE-2026-76681

cve-icon Vulnrichment

Updated: 2026-09-21T19:55:18.118Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:17:50.000

Modified: 2026-09-25T12:56:52.870

Link: CVE-2026-76681

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T12:30:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control