Junglewise Threat Intelligence

CVE-2026-76670: HPE EdgeConnect SD-WAN Orchestrator API privilege escalation

CVE-2026-76670 · Severity: critical · CVSS 9.9 · Published 2026-09-15

Technologies: Hpe EdgeConnect SD-WAN Orchestrator. Vendors: Hpe.

Executive brief

HPE EdgeConnect SD-WAN Orchestrator is a network management platform that controls wide-area network connectivity across enterprises. A privilege escalation vulnerability in its API allows authenticated users with low-level access to gain administrative control of the system, potentially compromising all network traffic and connected infrastructure managed by the orchestrator.

Technical details

The vulnerability exists in the API of EdgeConnect SD-WAN Orchestrator and allows privilege escalation from a low-privileged authenticated user to administrative level. An authenticated remote attacker can exploit this flaw to achieve complete system compromise. The vulnerability has been reported with a CVSS score of 9.9, indicating critical severity.

Affected products

  • HPE EdgeConnect SD-WAN Orchestrator

Timeline

  • 2026-09-15: disclosed

References

Related threats