Junglewise Threat Intelligence

CVE-2026-76704: Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator stored XSS in web management interface

CVE-2026-76704 · Severity: medium · CVSS 5.5 · Published 2026-09-15

Technologies: Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator. Vendors: Hewlett Packard Enterprise.

Executive brief

The EdgeConnect SD-WAN Orchestrator's web-based management interface contains a stored cross-site scripting (XSS) vulnerability that allows authenticated attackers to inject malicious script code. When a victim visits the affected interface, the injected code executes in their browser, potentially exposing sensitive data or allowing unauthorized actions within the application.

Technical details

A stored XSS vulnerability exists in the EdgeConnect SD-WAN Orchestrator web management interface that allows authenticated remote attackers to inject arbitrary JavaScript code. The injected script executes in the context of other users' browsers when they access the interface, potentially compromising the confidentiality and integrity of sensitive data processed by the application. Exploitation requires valid authentication credentials.

Affected products

  • Hewlett Packard Enterprise EdgeConnect SD-WAN Orchestrator <UNKNOWN>

Timeline

  • 2026-09-15: disclosed

References

Related threats