CVE-2026-76697: Authenticated Information Disclosure in HPE Networking EdgeConnect Enterprise Web-Based Management Interface
A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker must be authenticated to the web-based management interface with low-privilege credentials. No user interaction is required.
What is the likely impact of successful exploitation?
An attacker can access sensitive information from an affected gateway. The disclosed information could potentially be used to obtain further access to network services supported by the gateway.
Is an unauthenticated or local attacker affected?
The available information describes exploitation over the network by an authenticated low-privilege user. It does not indicate unauthenticated or local exploitation.