Description
A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Information Disclosure
Action: Patch
AI Analysis

Impact

A flaw in the web‑based management interface allows a remote attacker who has authenticated with a low‑privilege account to read sensitive data. The attacker can retrieve configuration or internal details that could be leveraged to expand access to network services provided by HPE EdgeConnect SD‑WAN Gateways. The key consequence is a breach of confidentiality that may serve as a stepping stone to more serious compromise.

Affected Systems

EdgeConnect SD‑WAN Gateways from Hewlett Packard Enterprise are impacted. No specific firmware or software versions are listed in the advisory, so all deployed gateways potentially require evaluation.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited evidence of active exploitation. The attack vector is remote, requiring the attacker to authenticate with a low‑privilege user on the web interface. Because the attacker must be authenticated, the risk is contingent on the existence of such accounts and the strength of authentication mechanisms. Organizations should treat this as a moderate risk until a patch is applied.

Generated by OpenCVE AI on September 15, 2026 at 23:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware or security patch from HPE that remediates the authentication check flaw.
  • Restrict access to the EdgeConnect web‑based management interface to trusted administrative networks and enforce strong, multi‑factor authentication for all accounts.
  • Review and tighten user privileges; disable or remove low‑privilege accounts that do not require access to sensitive configuration data.

Generated by OpenCVE AI on September 15, 2026 at 23:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.
Title Authenticated Information Disclosure in HPE Networking EdgeConnect Enterprise Web-Based Management Interface
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:41:37.774Z

Reserved: 2026-08-19T16:12:09.681Z

Link: CVE-2026-76697

cve-icon Vulnrichment

Updated: 2026-09-15T19:41:34.963Z

cve-icon NVD

Status : Received

Published: 2026-09-15T20:17:53.787

Modified: 2026-09-15T20:17:53.787

Link: CVE-2026-76697

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:30:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor