CVE-2026-76677
moderatePrivilege Escalation in HPE Aruba EdgeConnect SD-WAN Gateway API
A privilege escalation vulnerability exists in the API of HPE Aruba Networking EdgeConnect SD-WAN Gateways. A remote attacker with valid low-privileged API credentials can exploit the flaw to elevate themselves to administrative privileges on the web-management interface. Because the web-management interface fully controls the gateway, successful exploitation leads to complete system compromise of the affected appliance, including the ability to intercept or redirect SD-WAN traffic handled by it. Any organization running an affected EdgeConnect SD-WAN Gateway with API access reachable to low-privileged users is affected. No public proof-of-concept is known and the flaw is not on the CISA KEV list, so exploitation status is currently none known.
What to do: Apply the patched version specified in HPE's security bulletin as soon as it is available, prioritizing gateways whose API or web-management interface is reachable from untrusted networks. Restrict API and web-management access to trusted administrative networks or VPN, and review local low-privileged user accounts for validity. Audit authentication and privilege-change logs on gateways for anomalous administrative activity, and rotate admin credentials on any suspect device.
| HPE (HPE Aruba Networking) EdgeConnect SD-WAN Gateway | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could allow a remote low-privileged authenticated user to achieve administrative privilege on the web-management interface leading to complete system compromise.
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.