ZeroHour

CVE-2026-76680

moderate

Authenticated SSRF in HPE Aruba EdgeConnect SD-WAN Orchestrator API

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-76680 is a server-side request forgery (SSRF) flaw in the API of HPE Aruba Networking's EdgeConnect SD-WAN Orchestrator. A remote attacker who authenticates with only low-privilege credentials can trick the API into issuing requests to internal resources, effectively probing the internal structure of the Orchestrator host from the server's perspective. A successful exploit enables enumeration of internal hosts, services, and network layout, disclosing sensitive information beyond what the low-privilege account is authorized to see; the CVSS 3.1 base score is 8.5 (high), driven by high confidentiality impact across a changed scope. Any organization running an EdgeConnect SD-WAN Orchestrator (on-premises or cloud-hosted) is affected, particularly where low-privilege operator or read-only API accounts exist. No public proof-of-concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.

What to do: Apply the patched version identified in HPE's security advisory for EdgeConnect SD-WAN Orchestrator as soon as it is available, since the advisory data here does not list specific fixed versions. Restrict Orchestrator API and management access to trusted admin networks or VPN, and audit low-privilege API/operator accounts (including any shared or service accounts) for necessity and least-privilege scope. Monitor Orchestrator logs for API-originated outbound connection attempts to internal IPs or metadata-style endpoints, which are telltale signs of SSRF probing.

Affected
HPE Aruba Networking EdgeConnect SD-WAN Orchestrator
Estimated exposure
moderate≈1,000–10,000 Orchestrator deployments worldwide, with likely only hundreds to low-thousands of management interfaces internet-exposed (estimate) — EdgeConnect SD-WAN is deployed by thousands of enterprises that typically run one or a small number of Orchestrator instances each, and public internet scan data for exposed SD-WAN orchestrator management interfaces historically shows…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level.

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.