CVE-2026-76672
Analyzed Analyzed - Analysis Complete

SD-WAN Orchestrator Credential Exposure via Cache Sync

Vulnerability report for CVE-2026-76672, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-25

Assigner: Hewlett Packard Enterprise (HPE)

Description

A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-25
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
arubanetworks edgeconnect_sd-wan_orchestrator From 9.4.0 (inc) to 9.4.11 (exc)
arubanetworks edgeconnect_sd-wan_orchestrator From 9.5.0 (inc) to 9.5.9 (exc)
arubanetworks edgeconnect_sd-wan_orchestrator From 9.6.0 (inc) to 9.6.4 (exc)
arubanetworks edgeconnect_sd-wan_orchestrator 9.7.0
hpe edgeconnect_operating_system From 9.4.0.0 (inc) to 9.4.9.0 (exc)
hpe edgeconnect_operating_system From 9.5.0.0 (inc) to 9.5.9.0 (exc)
hpe edgeconnect_operating_system From 9.6.0.0 (inc) to 9.6.4.0 (exc)
hpe edgeconnect_operating_system 9.7.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the SD-WAN Orchestrator where an authenticated attacker with read-only access can send a crafted request to the cache synchronization endpoint. This may expose sensitive configuration details like third-party API tokens and credentials.

Detection Guidance

Detecting this vulnerability requires monitoring network traffic for unusual requests to the SD-WAN Orchestrator's cache synchronization endpoint. Check logs for repeated requests from authenticated users with read-only privileges. Inspect API responses for exposed sensitive tokens or credentials in plaintext.

Impact Analysis

An attacker could use exposed credentials to move laterally to external security platforms, potentially gaining unauthorized access to systems or data. This could lead to data breaches or further network compromise.

Compliance Impact

This vulnerability could lead to the exposure of sensitive configuration information, including third-party API tokens and credentials. Such a breach may violate compliance requirements under GDPR and HIPAA, which mandate strict protection of personal and health-related data. Unauthorized access to credentials could enable further attacks, exacerbating compliance violations.

Mitigation Strategies

Apply vendor patches or updates for the SD-WAN Orchestrator immediately. Restrict network access to the cache synchronization endpoint to trusted sources only. Review and rotate all third-party API tokens and credentials exposed in configurations. Monitor logs for unusual requests to the endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76672. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart