CVE-2026-76670
moderateAuthenticated Privilege Escalation in HPE EdgeConnect SD-WAN Orchestrator API
HPE Networking EdgeConnect SD-WAN Orchestrator contains privilege escalation flaws in its API that let a remote, low-privileged authenticated user escalate to administrative privileges. Exploitation is triggered by sending crafted requests to the orchestrator's API as any valid low-privilege account, with no user interaction required. A successful attacker gains full administrative control of the orchestrator, which HPE describes as leading to complete system compromise — and because the orchestrator centrally manages an organization's SD-WAN fabric, this also puts the wider network edge at risk. The issue affects customers running HPE Networking EdgeConnect SD-WAN Orchestrator (formerly Aruba EdgeConnect / Silver Peak Unity Orchestrator), in both on-premises and HPE-managed cloud deployments; specific affected versions were not stated in the advisory data. The flaw is rated critical (CVSS 9.9), but no public proof of concept exists, it is not in the CISA KEV catalog, and no in-the-wild exploitation is known.
What to do: Apply the patched release specified in HPE's security bulletin for EdgeConnect SD-WAN Orchestrator as soon as it is available, prioritizing any orchestrator whose management interface or API is reachable from untrusted networks. Restrict API and management-plane access to trusted admin networks or VPN, enforce least-privilege API roles, and rotate credentials for all low-privileged API accounts. Review orchestrator audit logs for anomalous privilege changes or unfamiliar API activity by low-privilege users.
| Hewlett Packard Enterprise (HPE) HPE Networking EdgeConnect SD-WAN Orchestrator | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.