CVE-2026-76688
moderateUnauthenticated authentication bypass in HPE Aruba EdgeConnect SD-WAN Orchestrator
CVE-2026-76688 is an authentication bypass vulnerability in the web-based management interface of the HPE Aruba Networking EdgeConnect SD-WAN Orchestrator. It allows an unauthenticated remote attacker to circumvent existing authentication controls; the CVSS 3.1 vector (AV:N/AC:H/PR:N/UI:R) indicates exploitation is network-reachable but requires high attack complexity and some user interaction. Successful exploitation grants the attacker administrative privileges, leading to complete compromise of the Orchestrator host — and, given the Orchestrator's central role in managing an SD-WAN fabric, potential downstream impact on the managed EdgeConnect environment. Organizations running on-premises or cloud-hosted EdgeConnect SD-WAN Orchestrator instances are affected. No public proof of concept is known, the flaw is not on the CISA KEV list, and there is no indication of in-the-wild exploitation at this time.
What to do: Apply the patched Orchestrator versions specified in HPE Aruba's security bulletin as soon as they are available, prioritizing any orchestrator whose management interface is reachable from the internet. Restrict management-plane access to trusted networks or VPN via ACLs/firewall rules, and verify cloud-hosted instances are on a patched release. Review orchestrator logs and admin account lists for unauthorized access, unexpected account creation, or configuration changes.
| HPE Aruba Networking EdgeConnect SD-WAN Orchestrator (web-based management interface) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.