CVE-2026-76689
Analyzed Analyzed - Analysis Complete

Stack-Based Buffer Overflow in HPE Configuration Processor

Vulnerability report for CVE-2026-76689, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-28

Assigner: Hewlett Packard Enterprise (HPE)

Description

A vulnerability exists in the configuration processing logic of the affected component where malformed input is improperly processed. An authenticated remote attacker with administrative privileges could exploit this vulnerability by providing specially crafted configuration data. Successful exploitation could result in a stack-based buffer overflow, potentially leading to remote code execution with root privileges or a denial of service due to a system crash.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-28
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
arubanetworks edgeconnect_sd-wan_orchestrator From 9.4.0 (inc) to 9.4.11 (exc)
arubanetworks edgeconnect_sd-wan_orchestrator From 9.5.0 (inc) to 9.5.9 (exc)
arubanetworks edgeconnect_sd-wan_orchestrator From 9.6.0 (inc) to 9.6.4 (exc)
arubanetworks edgeconnect_sd-wan_orchestrator 9.7.0
hpe edgeconnect_operating_system From 9.4.0.0 (inc) to 9.4.9.0 (exc)
hpe edgeconnect_operating_system From 9.5.0.0 (inc) to 9.5.9.0 (exc)
hpe edgeconnect_operating_system From 9.6.0.0 (inc) to 9.6.4.0 (exc)
hpe edgeconnect_operating_system 9.7.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stack-based buffer overflow vulnerability in the configuration processing logic of a component. It occurs when malformed input is improperly handled. An authenticated remote attacker with admin privileges can exploit this by sending specially crafted configuration data.

Detection Guidance

This vulnerability requires authenticated administrative access and involves malformed configuration data processing. Detection may involve monitoring for unusual configuration changes or crashes in the affected component. Check system logs for stack overflow errors or unexpected privilege escalations. No specific commands are provided in the available context.

Impact Analysis

Exploitation could lead to remote code execution with root privileges, allowing full system control. Alternatively, it may cause a denial of service by crashing the system. Both scenarios require an attacker to already have administrative access.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized remote code execution or denial of service with root privileges. Exploitation may lead to unauthorized access to sensitive data, violating confidentiality requirements under these regulations.

Mitigation Strategies

Immediately restrict administrative access to the affected component and apply vendor patches if available. Monitor system logs for unusual configuration changes or crashes. Disable remote configuration processing if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76689. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart