Description
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.
Published: 2026-09-15
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Apply Patch
AI Analysis

Impact

A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways allows an unauthenticated remote attacker to retrieve sensitive information. This information could be used to potentially gain further access to network services supported by the device.

Affected Systems

The affected product is Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways. No specific firmware versions are listed in the advisory, so the impact is presumed to apply to all releases known to the vendor that expose the vulnerable API.

Risk and Exploitability

The vulnerability has a CVSS score of 5.9, indicating moderate severity. The EPSS score is less than 1%, indicating a very low but non-zero exploitation probability. The disclosure is not tracked in the CISA KEV catalog. The attack vector is remote via the vulnerable API endpoint and requires no authentication; the attacker could use the accessed information to pursue further attacks against the network infrastructure.

Generated by OpenCVE AI on September 22, 2026 at 00:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Contact HPE support and apply any available firmware or patch that addresses the vulnerable API endpoint.
  • Modify firewall or network policies to restrict API traffic to a whitelisted set of internal IP addresses only.
  • Disable or remove the exposed API endpoint if the product settings allow, or otherwise block its traffic at the network perimeter.

Generated by OpenCVE AI on September 22, 2026 at 00:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System
CPEs cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.7.0:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:9.7.0.0:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System

Mon, 21 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways

Thu, 17 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 15 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.
Title Unauthenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Gateways
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Arubanetworks Edgeconnect Sd-wan Orchestrator
Hewlett Packard Enterprise (hpe) Edgeconnect Sd-wan Gateways
Hpe Edgeconnect Operating System
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-21T19:54:31.017Z

Reserved: 2026-08-19T16:12:09.681Z

Link: CVE-2026-76701

cve-icon Vulnrichment

Updated: 2026-09-21T19:54:26.487Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:17:54.617

Modified: 2026-09-28T13:50:04.580

Link: CVE-2026-76701

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T01:00:14Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function