Executive brief
HPE EdgeConnect SD-WAN Orchestrator is a network management platform that controls wide-area network connectivity across enterprises. A privilege escalation vulnerability in its API allows authenticated users with low-level access to gain administrative control of the system, potentially compromising all network traffic and connected infrastructure managed by the orchestrator.
Technical details
The vulnerability exists in the API of EdgeConnect SD-WAN Orchestrator and allows privilege escalation from a low-privileged authenticated user to administrative level. An authenticated remote attacker can exploit this flaw to achieve complete system compromise. The vulnerability has been reported with a CVSS score of 9.9, indicating critical severity.
Affected products
- HPE EdgeConnect SD-WAN Orchestrator
Timeline
- 2026-09-15: disclosed