ZeroHour

CVE-2026-76681

moderate

Broken Access Control in HPE Aruba EdgeConnect SD-WAN Orchestrator API

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-76681 is a broken access control flaw in the API of HPE Aruba Networking's EdgeConnect SD-WAN Orchestrator that lets an authenticated remote attacker holding only low privileges read sensitive information beyond their authorized scope. The flaw is triggered by an authenticated (low-privilege) request to the orchestrator's API, which returns data the account should not be able to see. Successful exploitation exposes sensitive information that could be leveraged to gain further access to network services managed by the orchestrator, making it a stepping stone toward deeper compromise of the SD-WAN environment. Affected parties are organizations running EdgeConnect SD-WAN Orchestrator deployments, particularly those with internet-facing orchestrators or many low-privilege user accounts. The vulnerability is rated high (CVSS 3.1 base 8.5), is not currently listed in CISA's KEV catalog, and no public proof-of-concept is known, indicating no observed in-the-wild exploitation at this time.

What to do: Apply the patch or version guidance in HPE Aruba's security advisory for CVE-2026-76681 as soon as the fixed release is available. Restrict orchestrator management/API exposure to trusted networks or VPN rather than the open internet, audit and prune low-privilege accounts, and review API access logs for anomalous data-retrieval activity by low-privilege users.

Affected
HPE Aruba Networking EdgeConnect SD-WAN Orchestrator
Estimated exposure
moderate≈ low thousands of orchestrator deployments worldwide, each managing many downstream SD-WAN edge appliances (hundreds of thousands of sites cumulatively) — EdgeConnect (formerly Silver Peak) orchestrators are typically deployed per-enterprise and often internet-facing for zero-touch provisioning, and public scan data for this product family historically shows only a few thousand exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privileges to access sensitive information beyond what is authorized by the user's existing privilege level. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by EdgeConnect SD-WAN Orchestrator.

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.