CVE-2026-76691: Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateway API Endpoint
Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be authenticated to the EdgeConnect SD-WAN Gateway API endpoint. The provided data does not identify which authenticated roles or privileges are sufficient.
What could successful exploitation allow?
A successful remote attacker could execute arbitrary commands as a privileged user on the gateway's underlying operating system. This could affect confidentiality, integrity, and availability.
Are gateways without API access exposed?
The vulnerability is described as existing in the gateway API endpoint. The provided information does not state whether the API is enabled by default or whether limiting API network exposure mitigates the issue.