CVE-2026-76678: Authenticated Command Injection Vulnerability leads to Remote Code Execution in EdgeConnect SD-WAN Gateways
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs low-privilege authenticated access to the affected gateway's API endpoint. No user interaction is required.
What is the potential impact after successful exploitation?
An attacker may escalate privileges and execute arbitrary system commands as root on the gateway's underlying operating system. This can affect confidentiality, integrity, and availability.
Is this exploitable remotely?
Yes. The attack vector is network-based, so an authenticated remote attacker able to reach the vulnerable API endpoint could exploit it.