Description
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could result in the disclosure of security-relevant configuration details and security feature status, which could be used to facilitate further attacks.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

A flaw in the API endpoint of HPE EdgeConnect SD-WAN Orchestrator enables an unauthenticated attacker to retrieve security‑relevant configuration details and the status of security features. The disclosure of such information constitutes a direct compromise of confidentiality and, because the exposed data can be leveraged to plan further attacks, it poses a potential stepping‑stone for additional compromise.

Affected Systems

The vulnerability affects Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific affected product versions are listed in the advisory; therefore, all current releases are potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, and the issue is not listed in CISA KEV, suggesting no known active exploitation. The attack vector is inferred to be remote through the exposed API, requiring no authentication. Because the vulnerability is unauthenticated and can be accessed by anyone who can reach the API, the risk is significant if the API is openly exposed. With proper network segmentation or inspection, the practical exploitation difficulty increases.

Generated by OpenCVE AI on September 15, 2026 at 23:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the HPE EdgeConnect SD‑WAN software update that removes the unauthenticated API access flaw.
  • Restrict the API endpoint to internal or VPN‑only traffic using firewall or ACL rules.
  • Continuously monitor logs for unexpected API requests and verify configuration visibility from the orchestrator.

Generated by OpenCVE AI on September 15, 2026 at 23:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could result in the disclosure of security-relevant configuration details and security feature status, which could be used to facilitate further attacks.
Title Unauthenticated Information Disclosure in EdgeConnect SD-WAN Orchestrator API allows exposure of sensitive data
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:45:51.195Z

Reserved: 2026-08-19T16:12:27.185Z

Link: CVE-2026-76706

cve-icon Vulnrichment

Updated: 2026-09-15T19:45:47.967Z

cve-icon NVD

Status : Received

Published: 2026-09-15T20:17:55.973

Modified: 2026-09-15T20:17:55.973

Link: CVE-2026-76706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:30:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor