CVE-2026-76704: Authenticated Stored Cross-Site Scripting (XSS) Vulnerability in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface
A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. Successful exploitation could allow an attacker to access sensitive information, potentially affecting the confidentiality and integrity of the data processed by the application.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need before they can exploit this issue?
The attacker must be authenticated to the affected web-based management interface and have high privileges. The attack can be performed remotely and does not require user interaction.
What is the expected security impact if exploitation succeeds?
An attacker may run script in another interface user's browser context and access sensitive information. The CVSS vector indicates low confidentiality and integrity impact, with no availability impact, and that the impact can extend beyond the vulnerable component's security scope.