Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-76673: EdgeConnect SD-WAN Orchestrator API may let attackers gain admin access

CVE-2026-76673 · published 11 days ago
Summary

The API used by the EdgeConnect SD-WAN Orchestrator can be accessed without proper login, allowing a remote user to obtain full administrative control of the system. This could let an attacker change settings, view data, or disrupt network operations. Apply the latest vendor updates and limit network access to the API to trusted hosts only.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
hewlett packard enterprise (hpe) edgeconnect sd-wan gateways <= 9.7.0
Original advisory text
Authentication Bypass Vulnerabilities in API of EdgeConnect SD-WAN Orchestrator
Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published15 Sep 2026
Updated27 Sep 2026
First seen15 Sep 2026
Sources
CVE-2026-76673 · MITRE
Track software like this
Free during beta