Junglewise Threat Intelligence

CVE-2026-76681: Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator API privilege escalation

CVE-2026-76681 · Severity: high · CVSS 8.5 · Published 2026-09-15

Technologies: Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator. Vendors: Hewlett Packard Enterprise.

Executive brief

EdgeConnect SD-WAN Orchestrator is a network management platform that controls software-defined wide-area networks. An authenticated attacker with basic user privileges can exploit an API vulnerability to access sensitive information and network configurations they should not be able to view, potentially enabling further attacks on the SD-WAN infrastructure.

Technical details

The vulnerability is an API privilege escalation flaw in EdgeConnect SD-WAN Orchestrator that allows authenticated low-privilege users to bypass authorization controls and access sensitive data. The attack requires network access to the API endpoint and valid credentials. Successful exploitation enables information disclosure that could facilitate lateral movement or attacks on connected network services.

Affected products

  • Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator

Timeline

  • 2026-09-15: disclosed

References

Related threats