CVE-2026-76706: Unauthenticated Information Disclosure in EdgeConnect SD-WAN Orchestrator API allows exposure of sensitive data
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could result in the disclosure of security-relevant configuration details and security feature status, which could be used to facilitate further attacks.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated remote attacker can exploit the affected API endpoint. No credentials or user interaction are required.
What information may be exposed?
The issue can disclose security-relevant configuration details and the status of security features. This information could help an attacker plan further attacks.
Does exploitation change configurations or disrupt service?
The provided impact information identifies confidentiality impact only. It does not indicate integrity or availability impact.