CVE-2026-76688: Authentication Bypass Vulnerabilities in the Web-Based Management Interface of EdgeConnect SD-WAN Orchestrator
Published Sep 15, 2026
·Updated
Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.
Affected Software
1 affected component
EdgeConnect SD-WAN Orchestrator
Event History
Sep 15, 2026
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of access could a successful attacker obtain?
A successful exploit could give an unauthenticated remote actor administrative privileges and result in complete compromise of the EdgeConnect SD-WAN Orchestrator host.
2
Does exploitation require credentials or user interaction?
The vulnerability is remotely reachable and requires no privileges, but successful exploitation requires user interaction. The attack complexity is rated high.