CVE-2026-76681
moderateBroken Access Control in HPE Aruba EdgeConnect SD-WAN Orchestrator API
CVE-2026-76681 is a broken access control flaw in the API of HPE Aruba Networking's EdgeConnect SD-WAN Orchestrator that lets an authenticated remote attacker holding only low privileges read sensitive information beyond their authorized scope. The flaw is triggered by an authenticated (low-privilege) request to the orchestrator's API, which returns data the account should not be able to see. Successful exploitation exposes sensitive information that could be leveraged to gain further access to network services managed by the orchestrator, making it a stepping stone toward deeper compromise of the SD-WAN environment. Affected parties are organizations running EdgeConnect SD-WAN Orchestrator deployments, particularly those with internet-facing orchestrators or many low-privilege user accounts. The vulnerability is rated high (CVSS 3.1 base 8.5), is not currently listed in CISA's KEV catalog, and no public proof-of-concept is known, indicating no observed in-the-wild exploitation at this time.
What to do: Apply the patch or version guidance in HPE Aruba's security advisory for CVE-2026-76681 as soon as the fixed release is available. Restrict orchestrator management/API exposure to trusted networks or VPN rather than the open internet, audit and prune low-privilege accounts, and review API access logs for anomalous data-retrieval activity by low-privilege users.
| HPE Aruba Networking EdgeConnect SD-WAN Orchestrator | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privileges to access sensitive information beyond what is authorized by the user's existing privilege level. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by EdgeConnect SD-WAN Orchestrator.
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.