ZeroHour

CVE-2026-76688

moderate

Unauthenticated authentication bypass in HPE Aruba EdgeConnect SD-WAN Orchestrator

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-76688 is an authentication bypass vulnerability in the web-based management interface of the HPE Aruba Networking EdgeConnect SD-WAN Orchestrator. It allows an unauthenticated remote attacker to circumvent existing authentication controls; the CVSS 3.1 vector (AV:N/AC:H/PR:N/UI:R) indicates exploitation is network-reachable but requires high attack complexity and some user interaction. Successful exploitation grants the attacker administrative privileges, leading to complete compromise of the Orchestrator host — and, given the Orchestrator's central role in managing an SD-WAN fabric, potential downstream impact on the managed EdgeConnect environment. Organizations running on-premises or cloud-hosted EdgeConnect SD-WAN Orchestrator instances are affected. No public proof of concept is known, the flaw is not on the CISA KEV list, and there is no indication of in-the-wild exploitation at this time.

What to do: Apply the patched Orchestrator versions specified in HPE Aruba's security bulletin as soon as they are available, prioritizing any orchestrator whose management interface is reachable from the internet. Restrict management-plane access to trusted networks or VPN via ACLs/firewall rules, and verify cloud-hosted instances are on a patched release. Review orchestrator logs and admin account lists for unauthorized access, unexpected account creation, or configuration changes.

Affected
HPE Aruba Networking EdgeConnect SD-WAN Orchestrator (web-based management interface)
Estimated exposure
moderate≈ low thousands of orchestrator instances (thousands of enterprises, but typically only one or a few orchestrators per deployment) — EdgeConnect SD-WAN Orchestrator is deployed by thousands of enterprise SD-WAN customers but each organization typically runs only one or a handful of orchestrator instances, many of which are internal-only rather than internet-facing, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.