Executive brief
EdgeConnect SD-WAN Orchestrator is a network management platform that controls and orchestrates SD-WAN edge devices. A vulnerability in its API allows an authenticated attacker with low privileges to perform server-side request forgery (SSRF) attacks, enabling them to probe internal systems and access sensitive information beyond their authorized privilege level.
Technical details
The API in EdgeConnect SD-WAN Orchestrator contains an SSRF vulnerability that can be exploited by authenticated users with low privileges. An attacker can abuse this to make requests to internal resources, enumerate the host's internal structure, and potentially disclose sensitive information. The vulnerability requires authentication but no additional user interaction.
Affected products
- HP EdgeConnect SD-WAN Orchestrator
Timeline
- 2026-09-15: disclosed