CVE-2026-76669
moderateAuthenticated Privilege Escalation in HPE EdgeConnect SD-WAN Orchestrator API
CVE-2026-76669 is a critical (CVSS 3.1: 9.9) privilege escalation vulnerability in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. It is triggered remotely by a low-privileged authenticated user sending crafted requests to the affected API, exploiting flaws that let them elevate their rights to those of an administrative user. Successful exploitation grants full administrative control of the orchestrator, which HPE states leads to complete system compromise — and, given the orchestrator's role, potentially control over the SD-WAN fabric it manages. Any organization running an affected EdgeConnect SD-WAN Orchestrator deployment with multiple user accounts is exposed to risk, particularly where low-privileged or tenant-level API access exists. No public proof-of-concept is known and the flaw is not listed in CISA's KEV catalog, so exploitation status is currently none known.
What to do: Apply the patched versions specified in HPE's security bulletin for EdgeConnect SD-WAN Orchestrator as soon as it is available. In the interim, restrict orchestrator API and management access to trusted VPN/administrative networks, audit and minimize low-privileged and tenant-level accounts with API access, and review authentication and privilege-change logs for anomalous activity. Rotate administrative credentials if any suspicious privilege elevation is observed.
| HPE (Hewlett Packard Enterprise) HPE Networking EdgeConnect SD-WAN Orchestrator | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.