Junglewise Threat Intelligence

CVE-2026-76701: HPE Networking EdgeConnect information disclosure in API endpoint

CVE-2026-76701 · Severity: medium · CVSS 5.9 · Published 2026-09-15

Executive brief

HPE Networking EdgeConnect SD-WAN Gateways are network appliances that manage secure wide-area network traffic for enterprises. A vulnerability in the API endpoint allows unauthenticated attackers to remotely retrieve sensitive information without requiring valid credentials, potentially enabling further compromise of network services.

Technical details

The vulnerability exists in an API endpoint of HPE Networking EdgeConnect SD-WAN Gateways that fails to properly enforce authentication controls. An unauthenticated remote attacker can access the affected endpoint over the network to retrieve sensitive information that could facilitate further attacks against network services. No authentication or special preconditions are required for exploitation. The disclosed information could enable lateral movement or targeted attacks on dependent systems. Patches are available; administrators should consult HPE security advisories for patched versions.

Affected products

  • HPE EdgeConnect <UNKNOWN>

Timeline

  • 2026-09-15: disclosed

References

Related threats