CVE-2026-76673
moderateUnauthenticated Auth Bypass in HPE Aruba EdgeConnect SD-WAN Orchestrator API
CVE-2026-76673 is an authentication-bypass flaw in the API of HPE Aruba Networking's EdgeConnect SD-WAN Orchestrator that lets an unauthenticated remote attacker circumvent existing authentication controls over the network, with no privileges or user interaction required (CVSS 3.1: 9.8). Successful exploitation grants the attacker administrative privileges on the Orchestrator, which amounts to complete compromise of the Orchestrator host and, by extension, potential control over the managed SD-WAN fabric. Any organization operating an EdgeConnect SD-WAN Orchestrator (on-premises or provider/cloud-hosted) is affected, particularly instances whose API interface is reachable from untrusted networks. No public proof-of-concept is known, the flaw is not on CISA's KEV list, and there are no reports of in-the-wild exploitation as of this analysis. The high severity and network-exploitable nature still make patching urgent for exposed deployments.
What to do: Apply HPE's patch immediately per the Aruba Networking security advisory and confirm your Orchestrator version against the affected/fixed list. Until patched, restrict Orchestrator API and management access to trusted networks or VPN and enforce allow-listing at edge firewalls. Review Orchestrator and host logs for unexplained unauthenticated API activity or new admin accounts, and rotate credentials and API keys if compromise is suspected.
| Hewlett Packard Enterprise (HPE Aruba Networking) EdgeConnect SD-WAN Orchestrator | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.