Junglewise Threat Intelligence

CVE-2026-76677: HPE EdgeConnect privilege escalation in API

CVE-2026-76677 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

EdgeConnect SD-WAN Gateways are network security appliances that manage secure Wide Area Network connectivity for enterprises. A privilege escalation flaw in the web management API allows authenticated users with low privileges to gain full administrative access, leading to complete system compromise and potential network-wide attacks.

Technical details

A privilege escalation vulnerability exists in the API of HPE EdgeConnect SD-WAN Gateways that allows a low-privileged authenticated user to escalate privileges to administrative level on the web management interface. The vulnerability requires network access to the API and an existing authenticated session (low-privilege credentials). Successful exploitation grants complete system compromise, enabling an attacker to modify network policies, intercept traffic, or disable security controls. Patches are available from HPE support.

Affected products

  • HPE EdgeConnect <UNKNOWN>

Timeline

  • 2026-09-15: disclosed

References

Related threats