ZeroHour

CVE-2026-76684

moderate

Unauthenticated Authentication Bypass in HPE EdgeConnect SD-WAN Orchestrator API

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-76684 is a flaw in the API of HPE Networking EdgeConnect SD-WAN Orchestrator that allows an unauthenticated remote attacker to circumvent the product's authentication controls. Exploitation is triggered over the network by sending specially crafted requests to the vulnerable API without valid credentials, though the CVSS vector (AV:N/AC:H) indicates exploit complexity is high, meaning the attack likely requires specific conditions or timing. A successful attacker gains administrative privileges, resulting in complete compromise of the EdgeConnect SD-WAN Orchestrator host, and by extension visibility and control over the managed SD-WAN environment. Affected parties are enterprises and service providers running HPE (formerly Aruba/Silver Peak) EdgeConnect SD-WAN Orchestrator, whether on-premises or cloud-hosted. There is no known public proof-of-concept and no indication of in-the-wild exploitation at this time (not in CISA KEV).

What to do: Apply the patched release specified in HPE's security bulletin for EdgeConnect SD-WAN Orchestrator as soon as it is available, since the flaw is unauthenticated and yields full host compromise. Until patched, restrict orchestrator API and management access to trusted VPN or internal management networks and enforce strict firewall/ACL rules, as well as MFA for administrative access where supported. Review orchestrator and API logs for unexplained unauthenticated requests, anomalous admin-level changes, or new administrative accounts, and monitor HPE advisories and CISA KEV for updated exploitation signals.

Affected
Hewlett Packard Enterprise (HPE) HPE Networking EdgeConnect SD-WAN Orchestrator
Estimated exposure
moderatelikely on the order of a few thousand orchestrator deployments worldwide, with only a subset (estimates in the hundreds to low thousands) reachable from the… — EdgeConnect is a major enterprise SD-WAN platform, but each customer typically operates only one or a few orchestrator instances, and public internet scans of SD-WAN management/orchestrator interfaces typically show hundreds to low…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerabilities have been identified in the API of HPE Networking EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.