Description
A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privileges to access sensitive information beyond what is authorized by the user's existing privilege level. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by EdgeConnect SD-WAN Orchestrator.
Published: 2026-09-15
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure
Action: Apply Patch
AI Analysis

Impact

A vulnerability in the EdgeConnect SD‑WAN Orchestrator API permits an authenticated attacker with low privileges to access sensitive information beyond the authorized scope of their account. Successful exploitation could expose data that might enable further compromise of network services managed by the Orchestrator. The flaw results from insufficient authorization checks, leading to an information disclosure vulnerability.

Affected Systems

The affected product is Hewlett Packard Enterprise's EdgeConnect SD‑WAN Gateways. No version range is specified in the advisory, so all releases of the Orchestrator API should be reviewed until vendor confirms the fix.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity impact. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack requires valid API credentials, but an authenticated user with even low‑level privileges can abuse the flaw. Remote attackers can retrieve confidential data over the network, and the disclosed information could form a stepping‑stone for further lateral movement or privilege escalation within the organization.

Generated by OpenCVE AI on September 15, 2026 at 22:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade HPE EdgeConnect SD‑WAN Orchestrator to a version that contains the fix or core security patch.
  • Limit API access by configuring firewall or VPN restrictions so only trusted management servers can reach the API endpoint.
  • Enforce least‑privilege for all API accounts and regularly review permissions; disable or remove accounts with unnecessary access.

Generated by OpenCVE AI on September 15, 2026 at 22:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privileges to access sensitive information beyond what is authorized by the user's existing privilege level. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by EdgeConnect SD-WAN Orchestrator.
Title Authenticated Information Disclosure Vulnerability in HPE Networking EdgeConnect SD-WAN Orchestrator API
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:23:41.297Z

Reserved: 2026-08-19T16:11:18.067Z

Link: CVE-2026-76681

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-15T20:17:50.000

Modified: 2026-09-15T20:17:50.000

Link: CVE-2026-76681

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:00:16Z

Weaknesses

No weakness.