Description
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.
Published: 2026-09-15
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Apply Patch
AI Analysis

Impact

A vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD‑WAN Gateways that allows an unauthenticated remote attacker to retrieve sensitive information. The exposed data could contain configuration details or credentials that may be leveraged to further compromise network services supported by the device.

Affected Systems

The affected product is Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific firmware versions are listed in the advisory, so the impact is presumed to apply to all releases known to the vendor that expose the vulnerable API.

Risk and Exploitability

The vulnerability has a CVSS score of 5.9, indicating moderate severity. The EPSS score is less than 1%, indicating a very low but non‑zero exploitation probability. The disclosure is not tracked in the CISA KEV catalog. The likely attack vector is remote, requiring no authentication, and an attacker could use the gained information to pursue further attacks against the network infrastructure.

Generated by OpenCVE AI on September 17, 2026 at 06:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact HPE support and apply any available firmware or patch that addresses the vulnerable API endpoint.
  • Modify firewall or network policies to restrict API traffic to a whitelisted set of internal IP addresses only.
  • Disable or remove the exposed API endpoint if the product settings allow, or otherwise block its traffic at the network perimeter.

Generated by OpenCVE AI on September 17, 2026 at 06:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 15 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.
Title Unauthenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Gateways
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:23:58.418Z

Reserved: 2026-08-19T16:12:09.681Z

Link: CVE-2026-76701

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:54.617

Modified: 2026-09-16T19:20:52.817

Link: CVE-2026-76701

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T07:00:24Z

Weaknesses

No weakness.