CVE-2026-76678
moderatePrivilege Escalation to Root Command Execution in HPE EdgeConnect SD-WAN Gateways
CVE-2026-76678 is a privilege escalation flaw in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways (formerly Aruba/Silver Peak EdgeConnect). A remote attacker who authenticates with a low-privilege account can send crafted requests to the vulnerable API to escalate their privileges and execute arbitrary system commands with root privileges on the gateway's underlying operating system. Successful exploitation gives the attacker full control of the appliance, compromising the confidentiality, integrity, and availability of SD-WAN traffic handled by that gateway. Any organization running affected EdgeConnect SD-WAN gateway appliances is impacted, particularly branch and data-center edge deployments that expose the management/API interface. The flaw is rated high severity (CVSS 3.1: 8.8), but it is not listed in CISA's KEV catalog and no public proof of concept is known, so exploitation status is currently none known.
What to do: Apply the patched software version from HPE's security advisory for EdgeConnect SD-WAN Gateways as soon as it is available. Until patched, restrict management and API access to trusted administrative networks or VPN only, and review low-privilege user accounts on gateways for signs of abuse. Monitor gateway logs for unexpected privileged command execution and anomalous authenticated API activity.
| Hewlett Packard Enterprise (HPE) HPE Networking EdgeConnect SD-WAN Gateway | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.