ZeroHour

CVE-2026-76687

moderate

Privilege Escalation to Root Command Execution in HPE EdgeConnect SD-WAN Orchestrator

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-76687 is a high-severity (CVSS 7.5) privilege escalation vulnerability in an API endpoint of the HPE Networking EdgeConnect SD-WAN Orchestrator. A remote attacker who already possesses a low-privilege authenticated account (network access, high attack complexity, low privileges required) can abuse the flawed endpoint to escalate their privileges and execute arbitrary system commands as root on the underlying operating system. Because the Orchestrator centrally manages SD-WAN appliances and their configurations, compromise of the underlying host could expose tenant credentials, topology data, and the ability to push malicious configuration to managed edge appliances. Organizations running EdgeConnect SD-WAN Orchestrator instances — especially internet-facing management interfaces — are affected. As of this writing there is no known public proof of concept and no confirmed in-the-wild exploitation, though EdgeConnect Orchestrators have historically been targeted by attackers, so active exploitation cannot be ruled out.

What to do: Apply the patched Orchestrator version identified in HPE's security bulletin for CVE-2026-76687 as soon as it is available, since authentication is required but any low-privilege API account can potentially pivot to root command execution. Restrict Orchestrator management and API access to trusted administrative networks or VPN rather than exposing it to the internet, audit and prune low-privilege API/local accounts, and rotate credentials. Review Orchestrator logs for anomalous privileged API activity and unexpected root-level command execution on the underlying host.

Affected
Hewlett Packard Enterprise (HPE) HPE Networking EdgeConnect SD-WAN Orchestrator
Estimated exposure
moderatelikely hundreds to low thousands of exposed Orchestrator instances worldwide (thousands of enterprise SD-WAN deployments) — EdgeConnect SD-WAN is an enterprise product with a customer base typically measured in the thousands of organizations, and each deployment usually runs only one or a few Orchestrator instances — some internet-facing, as demonstrated by…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.