CVE-2026-76687: Authenticated Arbitrary File Write Leading to Remote Code Execution in EdgeConnect SD-WAN Orchestrator
Published Sep 15, 2026
·Updated
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.
Affected Software
1 affected component
HPE Networking EdgeConnect SD-WAN Orchestrator
Event History
Sep 15, 2026
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
DescriptionSeverity
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker must be remotely able to authenticate to the Orchestrator API using a low-privilege account. No user interaction is required, but exploitation has high attack complexity.
2
What is the potential impact after successful exploitation?
A successful attacker may escalate privileges and execute arbitrary system commands as root on the underlying operating system. This can affect confidentiality, integrity, and availability.