Junglewise Threat Intelligence

CVE-2026-76688: Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator auth bypass in management interface

CVE-2026-76688 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator. Vendors: Hewlett Packard Enterprise.

Executive brief

The EdgeConnect SD-WAN Orchestrator is a management platform for software-defined wide-area networks used in enterprise environments. An unauthenticated attacker can bypass authentication controls in the web-based management interface and gain administrative privileges, potentially compromising the entire SD-WAN infrastructure and any networks it manages.

Technical details

An authentication bypass vulnerability exists in the web-based management interface of EdgeConnect SD-WAN Orchestrator, allowing unauthenticated remote attackers to circumvent authentication controls via network access. Successful exploitation grants administrative privileges and complete compromise of the orchestrator host. The vulnerability is remotely exploitable without requiring authentication or user interaction.

Affected products

  • Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator <UNKNOWN>

Timeline

  • 2026-09-15: disclosed

References

Related threats