CVE-2026-76680
moderateAuthenticated SSRF in HPE Aruba EdgeConnect SD-WAN Orchestrator API
CVE-2026-76680 is a server-side request forgery (SSRF) flaw in the API of HPE Aruba Networking's EdgeConnect SD-WAN Orchestrator. A remote attacker who authenticates with only low-privilege credentials can trick the API into issuing requests to internal resources, effectively probing the internal structure of the Orchestrator host from the server's perspective. A successful exploit enables enumeration of internal hosts, services, and network layout, disclosing sensitive information beyond what the low-privilege account is authorized to see; the CVSS 3.1 base score is 8.5 (high), driven by high confidentiality impact across a changed scope. Any organization running an EdgeConnect SD-WAN Orchestrator (on-premises or cloud-hosted) is affected, particularly where low-privilege operator or read-only API accounts exist. No public proof-of-concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.
What to do: Apply the patched version identified in HPE's security advisory for EdgeConnect SD-WAN Orchestrator as soon as it is available, since the advisory data here does not list specific fixed versions. Restrict Orchestrator API and management access to trusted admin networks or VPN, and audit low-privilege API/operator accounts (including any shared or service accounts) for necessity and least-privilege scope. Monitor Orchestrator logs for API-originated outbound connection attempts to internal IPs or metadata-style endpoints, which are telltale signs of SSRF probing.
| HPE Aruba Networking EdgeConnect SD-WAN Orchestrator | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level.
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.