CVE-2026-76706
Analyzed Analyzed - Analysis Complete

Information Disclosure in HPE Networking EdgeConnect SD-WAN Orchestrator

Vulnerability report for CVE-2026-76706, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-25

Assigner: Hewlett Packard Enterprise (HPE)

Description

A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could result in the disclosure of security-relevant configuration details and security feature status, which could be used to facilitate further attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-25
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
arubanetworks edgeconnect_sd-wan_orchestrator From 9.4.0 (inc) to 9.4.11 (exc)
arubanetworks edgeconnect_sd-wan_orchestrator From 9.5.0 (inc) to 9.5.9 (exc)
arubanetworks edgeconnect_sd-wan_orchestrator From 9.6.0 (inc) to 9.6.4 (exc)
arubanetworks edgeconnect_sd-wan_orchestrator 9.7.0
hpe edgeconnect_operating_system From 9.4.0.0 (inc) to 9.4.9.0 (exc)
hpe edgeconnect_operating_system From 9.5.0.0 (inc) to 9.5.9.0 (exc)
hpe edgeconnect_operating_system From 9.6.0.0 (inc) to 9.6.4.0 (exc)
hpe edgeconnect_operating_system 9.7.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator. It allows an unauthenticated remote attacker to access sensitive information without needing to log in. Exploitation could reveal security-related configuration details and the status of security features.

Impact Analysis

An attacker could use this flaw to gather critical system information, which might help them plan further attacks. This could lead to unauthorized access, data breaches, or disruption of network services if additional vulnerabilities are exploited.

Compliance Impact

This vulnerability could lead to unauthorized disclosure of sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance penalties if such breaches occur due to inadequate security measures.

Mitigation Strategies

Apply the latest security patches provided by HPE for the EdgeConnect SD-WAN Orchestrator. Ensure the API endpoint is not exposed to untrusted networks and restrict access via firewalls or network segmentation. Monitor for unusual API requests or data exfiltration attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76706. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart