Junglewise Threat Intelligence

CVE-2026-76673: Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator authentication bypass in API

CVE-2026-76673 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Technologies: Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator. Vendors: Hewlett Packard Enterprise.

Executive brief

EdgeConnect SD-WAN Orchestrator is a network management platform used to control software-defined wide-area networks. A vulnerability in its API allows unauthenticated attackers to bypass authentication controls and gain administrative access, potentially leading to complete compromise of the orchestrator and control of the entire SD-WAN infrastructure.

Technical details

The API in EdgeConnect SD-WAN Orchestrator fails to properly enforce authentication on certain endpoints, allowing unauthenticated remote access. An attacker can exploit this to bypass authentication controls and escalate privileges to administrator level, gaining full control of the orchestrator host and potentially the entire managed SD-WAN environment.

Affected products

  • Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator

Timeline

  • 2026-09-15: disclosed

References

Related threats