Junglewise Threat Intelligence

CVE-2026-76669: HPE EdgeConnect SD-WAN Orchestrator API privilege escalation

CVE-2026-76669 · Severity: critical · CVSS 9.9 · Published 2026-09-15

Technologies: Hpe EdgeConnect SD-WAN Orchestrator. Vendors: Hpe.

Executive brief

HPE EdgeConnect SD-WAN Orchestrator is a network management platform that controls SD-WAN traffic for enterprise networks. A privilege escalation flaw in its API allows an authenticated user with limited access to gain administrative control over the entire system, potentially enabling an attacker to redirect network traffic, steal data, or sabotage network operations.

Technical details

A privilege escalation vulnerability exists in the API of HPE EdgeConnect SD-WAN Orchestrator that allows a remote, authenticated user with low privileges to escalate to administrative access. The vulnerability requires prior authentication but can be exploited remotely, leading to complete system compromise and unauthenticated access to all network management functions.

Affected products

  • HPE EdgeConnect SD-WAN Orchestrator

Timeline

  • 2026-09-15: disclosed

References

Related threats