ZeroHour

CVE-2026-76673

moderate

Unauthenticated Auth Bypass in HPE Aruba EdgeConnect SD-WAN Orchestrator API

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-76673 is an authentication-bypass flaw in the API of HPE Aruba Networking's EdgeConnect SD-WAN Orchestrator that lets an unauthenticated remote attacker circumvent existing authentication controls over the network, with no privileges or user interaction required (CVSS 3.1: 9.8). Successful exploitation grants the attacker administrative privileges on the Orchestrator, which amounts to complete compromise of the Orchestrator host and, by extension, potential control over the managed SD-WAN fabric. Any organization operating an EdgeConnect SD-WAN Orchestrator (on-premises or provider/cloud-hosted) is affected, particularly instances whose API interface is reachable from untrusted networks. No public proof-of-concept is known, the flaw is not on CISA's KEV list, and there are no reports of in-the-wild exploitation as of this analysis. The high severity and network-exploitable nature still make patching urgent for exposed deployments.

What to do: Apply HPE's patch immediately per the Aruba Networking security advisory and confirm your Orchestrator version against the affected/fixed list. Until patched, restrict Orchestrator API and management access to trusted networks or VPN and enforce allow-listing at edge firewalls. Review Orchestrator and host logs for unexplained unauthenticated API activity or new admin accounts, and rotate credentials and API keys if compromise is suspected.

Affected
Hewlett Packard Enterprise (HPE Aruba Networking) EdgeConnect SD-WAN Orchestrator
Estimated exposure
moderatethousands of enterprise SD-WAN deployments; likely hundreds to low thousands of internet-reachable Orchestrator instances — Aruba EdgeConnect (formerly Silver Peak) serves an enterprise customer base typically measured in the low thousands, with generally one or a few Orchestrator hosts per deployment and only a subset exposed to the internet in public scan…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.