Description
Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the web-based management interface of the EdgeConnect SD‑WAN Orchestrator and could potentially allow an unauthenticated remote actor to bypass existing authentication controls. By successfully exploiting this flaw, an attacker can obtain administrative privileges, enabling full compromise of the Orchestrator host. This provides an attacker with the ability to alter network policies, access sensitive data, and potentially affect the entire SD‑WAN deployment.

Affected Systems

The flaw affects Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. Specific version information is not provided in the advisory, implying that all current releases are potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 7.5 classifies this issue as high severity. The EPSS probability of exploitation at the moment, but the nature of the vulnerability—remote authentication bypass resulting in administrative control—places it listed but the attack vector is likely through the publicly reachable web interface, meaning an attacker could send crafted HTTP requests to circumvent login checks and elevate privileges.

Generated by OpenCVE AI on September 17, 2026 at 06:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the latest firmware or patch release for EdgeConnect SD‑WAN Gateways on the HPE support site and apply the update as soon as possible.
  • Restrict access to the Orchestrator web interface to a limited, trusted IP range or VPN tunnel to reduce the attack surface.
  • Configure or enforce multi‑factor authentication and strong password policies for the administration account.
  • Enable logging and regularly review authentication logs for suspicious access attempts.

Generated by OpenCVE AI on September 17, 2026 at 06:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Tue, 15 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.
Title Authentication Bypass Vulnerabilities in the Web-Based Management Interface of EdgeConnect SD-WAN Orchestrator
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:23:47.687Z

Reserved: 2026-08-19T16:11:34.861Z

Link: CVE-2026-76688

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:50.797

Modified: 2026-09-16T19:20:52.817

Link: CVE-2026-76688

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T07:00:24Z

Weaknesses

No weakness.