Junglewise Threat Intelligence

CVE-2026-76697: HPE Networking EdgeConnect SD-WAN Gateway information disclosure in web management interface

CVE-2026-76697 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Executive brief

HPE Networking EdgeConnect SD-WAN Gateways are network appliances used to manage and optimize wide-area network traffic. A vulnerability in their web-based management interface allows attackers with low-privilege credentials to retrieve sensitive information that could facilitate unauthorized access to network services. This information leakage could enable lateral movement within a network or compromise of connected services.

Technical details

The vulnerability is an information disclosure flaw in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways. It requires authentication with low-privilege credentials to exploit, meaning an attacker must first obtain valid login access or credentials. The vulnerability allows an attacker to retrieve sensitive data that could be leveraged to gain unauthorized access to network services supported by the EdgeConnect platform. The exact nature of the disclosed information and vulnerable component is not fully detailed in available sources, but the attack vector is network-based and requires user authentication.

Affected products

  • HPE EdgeConnect SD-WAN Gateway <UNKNOWN>

Timeline

  • 2026-09-15: disclosed

References

Related threats