CVE-2026-76672
moderateAuthenticated Secret Disclosure in HPE SD-WAN Orchestrator Cache Sync Endpoint
CVE-2026-76672 is a critical (CVSS 9.9) information disclosure flaw in HPE's SD-WAN Orchestrator affecting the cache synchronization endpoint. An authenticated remote attacker holding only read-only privileges can send a specially crafted request to that endpoint, which returns sensitive configuration data without further authorization checks. Successful exploitation discloses third-party API tokens and credentials, which could enable lateral movement into external security platforms integrated with the orchestrator. The vulnerability affects HPE SD-WAN Orchestrator deployments exposed to authenticated users; no specific version ranges were provided in the advisory data. There is no known public proof of concept and the flaw is not on CISA's KEV list, so exploitation status is currently none known.
What to do: Apply the patched release identified in HPE's security bulletin for the SD-WAN Orchestrator as soon as it is available. Restrict orchestrator management access to trusted admin networks or VPN, and audit logs for unusual requests to the cache synchronization endpoint from read-only accounts. Rotate any third-party API tokens and credentials configured on the orchestrator, since exposed secrets could enable lateral movement to connected security platforms.
| HPE SD-WAN Orchestrator | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.