ZeroHour

CVE-2026-76670

moderate

Authenticated Privilege Escalation in HPE EdgeConnect SD-WAN Orchestrator API

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

HPE Networking EdgeConnect SD-WAN Orchestrator contains privilege escalation flaws in its API that let a remote, low-privileged authenticated user escalate to administrative privileges. Exploitation is triggered by sending crafted requests to the orchestrator's API as any valid low-privilege account, with no user interaction required. A successful attacker gains full administrative control of the orchestrator, which HPE describes as leading to complete system compromise — and because the orchestrator centrally manages an organization's SD-WAN fabric, this also puts the wider network edge at risk. The issue affects customers running HPE Networking EdgeConnect SD-WAN Orchestrator (formerly Aruba EdgeConnect / Silver Peak Unity Orchestrator), in both on-premises and HPE-managed cloud deployments; specific affected versions were not stated in the advisory data. The flaw is rated critical (CVSS 9.9), but no public proof of concept exists, it is not in the CISA KEV catalog, and no in-the-wild exploitation is known.

What to do: Apply the patched release specified in HPE's security bulletin for EdgeConnect SD-WAN Orchestrator as soon as it is available, prioritizing any orchestrator whose management interface or API is reachable from untrusted networks. Restrict API and management-plane access to trusted admin networks or VPN, enforce least-privilege API roles, and rotate credentials for all low-privileged API accounts. Review orchestrator audit logs for anomalous privilege changes or unfamiliar API activity by low-privilege users.

Affected
Hewlett Packard Enterprise (HPE) HPE Networking EdgeConnect SD-WAN Orchestrator
Estimated exposure
moderate≈1,000–10,000 orchestrator deployments worldwide, each managing an enterprise SD-WAN with many sites and users — EdgeConnect is an enterprise SD-WAN product typically deployed as one orchestrator per customer environment, and public internet scanning around prior Aruba EdgeConnect orchestrator advisories has consistently shown exposed instances in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.