CVE-2026-76673: Authentication Bypass Vulnerabilities in API of EdgeConnect SD-WAN Orchestrator
Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated remote actor could exploit the affected API. No existing account or user interaction is required according to the supplied severity vector.
What level of access could an attacker obtain?
Successful exploitation could grant administrative privileges and lead to complete compromise of the EdgeConnect SD-WAN Orchestrator host.
What should be prioritized during triage?
Prioritize systems running EdgeConnect SD-WAN Orchestrator whose API is reachable by untrusted remote actors, because the issue is rated critical and can be exploited without authentication.