CVE-2026-76701: Unauthenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Gateways
Published Sep 15, 2026
·Updated
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.
Affected Software
1 affected component
HPE Networking EdgeConnect SD-WAN Gateways
Event History
Sep 15, 2026
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
DescriptionSeverity
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated remote attacker could exploit the affected API endpoint. No account or prior authentication is required, but the attack complexity is rated high.
2
What is the security impact?
An attacker could retrieve sensitive information from an affected gateway. The disclosed information could potentially be used to obtain further access to network services supported by the gateway.