ZeroHour

CVE-2026-76672

moderate

Authenticated Secret Disclosure in HPE SD-WAN Orchestrator Cache Sync Endpoint

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-76672 is a critical (CVSS 9.9) information disclosure flaw in HPE's SD-WAN Orchestrator affecting the cache synchronization endpoint. An authenticated remote attacker holding only read-only privileges can send a specially crafted request to that endpoint, which returns sensitive configuration data without further authorization checks. Successful exploitation discloses third-party API tokens and credentials, which could enable lateral movement into external security platforms integrated with the orchestrator. The vulnerability affects HPE SD-WAN Orchestrator deployments exposed to authenticated users; no specific version ranges were provided in the advisory data. There is no known public proof of concept and the flaw is not on CISA's KEV list, so exploitation status is currently none known.

What to do: Apply the patched release identified in HPE's security bulletin for the SD-WAN Orchestrator as soon as it is available. Restrict orchestrator management access to trusted admin networks or VPN, and audit logs for unusual requests to the cache synchronization endpoint from read-only accounts. Rotate any third-party API tokens and credentials configured on the orchestrator, since exposed secrets could enable lateral movement to connected security platforms.

Affected
HPE SD-WAN Orchestrator
Estimated exposure
moderate≈1,000–5,000 orchestrator deployments worldwide (one management instance per enterprise SD-WAN estate) — SD-WAN orchestrators are deployed roughly once per enterprise customer, and HPE/Aruba EdgeConnect's enterprise customer base plus typical internet-scan counts of exposed management interfaces suggest a four-digit number of reachable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.