ZeroHour

CVE-2026-76669

moderate

Authenticated Privilege Escalation in HPE EdgeConnect SD-WAN Orchestrator API

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-76669 is a critical (CVSS 3.1: 9.9) privilege escalation vulnerability in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. It is triggered remotely by a low-privileged authenticated user sending crafted requests to the affected API, exploiting flaws that let them elevate their rights to those of an administrative user. Successful exploitation grants full administrative control of the orchestrator, which HPE states leads to complete system compromise — and, given the orchestrator's role, potentially control over the SD-WAN fabric it manages. Any organization running an affected EdgeConnect SD-WAN Orchestrator deployment with multiple user accounts is exposed to risk, particularly where low-privileged or tenant-level API access exists. No public proof-of-concept is known and the flaw is not listed in CISA's KEV catalog, so exploitation status is currently none known.

What to do: Apply the patched versions specified in HPE's security bulletin for EdgeConnect SD-WAN Orchestrator as soon as it is available. In the interim, restrict orchestrator API and management access to trusted VPN/administrative networks, audit and minimize low-privileged and tenant-level accounts with API access, and review authentication and privilege-change logs for anomalous activity. Rotate administrative credentials if any suspicious privilege elevation is observed.

Affected
HPE (Hewlett Packard Enterprise) HPE Networking EdgeConnect SD-WAN Orchestrator
Estimated exposure
moderate≈ hundreds to low thousands of internet-exposed orchestrator instances (order of magnitude, clearly an estimate) — SD-WAN orchestrators are typically deployed once per enterprise network, and public internet scan data for HPE/Aruba EdgeConnect (formerly Silver Peak Unity) Orchestrator has historically shown a few hundred to low thousands of exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.