Junglewise Threat Intelligence

CVE-2026-76684: HPE Networking EdgeConnect SD-WAN Orchestrator API authentication bypass

CVE-2026-76684 · Severity: high · CVSS 8.1 · Published 2026-09-15

Vendors: HPE Networking.

Executive brief

HPE's EdgeConnect SD-WAN Orchestrator manages enterprise wide-area network traffic across branches and cloud. An unauthenticated attacker can bypass API authentication controls and gain administrative access to the orchestrator, enabling complete system compromise and control over all connected SD-WAN infrastructure.

Technical details

An authentication bypass vulnerability exists in the EdgeConnect SD-WAN Orchestrator's REST API that allows an unauthenticated remote attacker to bypass access controls. Successful exploitation grants administrative privileges on the orchestrator host, potentially enabling command execution, configuration manipulation, and lateral movement within the SD-WAN fabric. No preconditions such as valid credentials or user interaction are required.

Affected products

  • HPE Networking EdgeConnect SD-WAN Orchestrator

Timeline

  • 2026-09-15: disclosed

References

Related threats