Description
A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to escalate privileges beyond their authorized level, and execute arbitrary code on a vulnerable system.
Published: 2026-09-15
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

The flaw enables an authenticated remote attacker who already holds a high‑privilege account on an HPE EdgeConnect SD‑WAN Gateway to raise their privileges beyond the authorized level and run arbitrary code. This can lead to full compromise of the device, threatening confidentiality, integrity, and availability of the network services it controls.

Affected Systems

Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. The vulnerability affects all product instances that expose the command‑line interface to authenticated users; specific firmware versions are not disclosed.

Risk and Exploitability

The CVSS score of 6.6 reflects a moderate severity. The EPSS score is <1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exfiltration requires remote authentication with a high‑privilege account; once privilege is escalated, the attacker can execute arbitrary commands on the device.

Generated by OpenCVE AI on September 20, 2026 at 12:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available firmware or software update from HPE that resolves the privilege escalation flaw.
  • Restrict command‑line interface access to only the minimal set of privileged administrators and remove unnecessary high‑privilege accounts.
  • Limit or disable remote CLI access, confining it to trusted internal networks or VPN‑only connections.

Generated by OpenCVE AI on September 20, 2026 at 12:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System
CPEs cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.7.0:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:9.7.0.0:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to escalate privileges beyond their authorized level, and execute arbitrary code on a vulnerable system.
Title Authenticated Privilege Escalation Vulnerability in the Command Line Interface of HPE Networking EdgeConnect SD-WAN Gateways
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Arubanetworks Edgeconnect Sd-wan Orchestrator
Hewlett Packard Enterprise (hpe) Edgeconnect Sd-wan Gateways
Hpe Edgeconnect Operating System
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:43:35.201Z

Reserved: 2026-08-19T16:11:34.861Z

Link: CVE-2026-76694

cve-icon Vulnrichment

Updated: 2026-09-15T19:43:31.530Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:17:52.270

Modified: 2026-09-28T13:47:46.323

Link: CVE-2026-76694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T12:15:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management