Junglewise Threat Intelligence

CVE-2026-76706: HPE Networking EdgeConnect SD-WAN Orchestrator API information disclosure

CVE-2026-76706 · Severity: medium · CVSS 5.3 · Published 2026-09-15

Vendors: HPE Networking.

Executive brief

HPE Networking EdgeConnect SD-WAN Orchestrator is a management platform for software-defined wide-area networks. An unauthenticated remote attacker can exploit an API endpoint to obtain sensitive configuration details and security settings, which could enable reconnaissance for further attacks on the network infrastructure.

Technical details

An unauthenticated API endpoint in the Orchestrator exposes sensitive configuration data and security feature status without authentication. The vulnerability is exploitable remotely with no user interaction required, allowing attackers to gather reconnaissance information about the SD-WAN deployment to facilitate subsequent targeted attacks.

Affected products

  • HPE Networking EdgeConnect SD-WAN Orchestrator

Timeline

  • 2026-09-15: disclosed

References

Related threats