CVE-2026-76681: Authenticated Information Disclosure Vulnerability in HPE Networking EdgeConnect SD-WAN Orchestrator API
A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privileges to access sensitive information beyond what is authorized by the user's existing privilege level. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by EdgeConnect SD-WAN Orchestrator.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker must be able to authenticate remotely to the EdgeConnect SD-WAN Orchestrator API with a low-privileged account. No user interaction is required.
What is the likely impact of successful exploitation?
A low-privileged authenticated user may retrieve sensitive information beyond their authorized privilege level. The disclosed information could potentially be used to gain further access to network services supported by the Orchestrator.