CVE-2026-76680
Analyzed Analyzed - Analysis Complete

Server-Side Request Forgery in EdgeConnect SD-WAN Orchestrator

Vulnerability report for CVE-2026-76680, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-25

Assigner: Hewlett Packard Enterprise (HPE)

Description

Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-25
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
arubanetworks edgeconnect_sd-wan_orchestrator From 9.4.0 (inc) to 9.4.11 (exc)
arubanetworks edgeconnect_sd-wan_orchestrator From 9.5.0 (inc) to 9.5.9 (exc)
arubanetworks edgeconnect_sd-wan_orchestrator From 9.6.0 (inc) to 9.6.4 (exc)
arubanetworks edgeconnect_sd-wan_orchestrator 9.7.0
hpe edgeconnect_operating_system From 9.4.0.0 (inc) to 9.4.9.0 (exc)
hpe edgeconnect_operating_system From 9.5.0.0 (inc) to 9.5.9.0 (exc)
hpe edgeconnect_operating_system From 9.6.0.0 (inc) to 9.6.4.0 (exc)
hpe edgeconnect_operating_system 9.7.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves flaws in the API of EdgeConnect SD-WAN Orchestrator that allow a remote attacker with low-level authentication to perform server-side request forgery (SSRF) attacks. This could enable the attacker to gather details about the internal setup of the host system, potentially exposing sensitive information beyond their authorized access level.

Detection Guidance

Detecting this SSRF vulnerability requires monitoring API requests to the EdgeConnect SD-WAN Orchestrator for unusual internal network enumeration attempts. Check logs for outbound requests to internal IP ranges or unexpected host headers. Use network traffic analysis tools like tcpdump or Wireshark to inspect API traffic for anomalies such as requests to localhost or internal subnets.

Impact Analysis

An attacker could exploit this to learn about your internal network structure, which may lead to further attacks like data breaches or unauthorized access to sensitive systems. The impact includes potential exposure of confidential information and compromise of network integrity.

Compliance Impact

This vulnerability could lead to unauthorized disclosure of sensitive data, violating compliance requirements under GDPR, HIPAA, or other regulations. Non-compliance may result in legal penalties, fines, or reputational damage due to data exposure.

Mitigation Strategies

Update EdgeConnect SD-WAN Orchestrator to the latest patched version immediately to address the SSRF vulnerability. Restrict network access to the API using firewalls or network segmentation to limit exposure. Monitor API logs for unusual requests or patterns indicating exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76680. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart