Executive brief
HPE EdgeConnect SD-WAN Orchestrator is a network management platform for software-defined wide-area networks. A flaw in its API allows authenticated users with low privileges to escalate to root access and execute arbitrary commands on the underlying operating system, potentially compromising the entire network infrastructure.
Technical details
The vulnerability exists in an API endpoint that lacks proper privilege checks, allowing a low-privilege authenticated remote attacker to perform unauthorized operations. An attacker can leverage this flaw to execute arbitrary system commands with root privileges on the underlying operating system. The attack requires valid authentication credentials but no additional user interaction.
Affected products
- HPE EdgeConnect SD-WAN Orchestrator
Timeline
- 2026-09-15: disclosed