Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
6342 articles · 219800 vulns · 36/41 feeds (7d)
← Back to list
8.5
CVE-2026-76681
Hewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN Gateways

Authenticated Information Disclosure Vulnerability in HPE Networking EdgeConnect SD-WAN Orchestrator API

Description

A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privileges to access sensitive information beyond what is authorized by the user's existing privilege level. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by EdgeConnect SD-WAN Orchestrator.

Affected Products

VendorProductVersions
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.7.0, 9.6.0, 9.5.0, 9.4.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
arubaedgeconnectcert_advisory90%

References

  • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US

Related News (3 articles)

Tier B
BSI Advisories4d ago
[NEU] [hoch] Aruba EdgeConnect: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR4d ago
Multiples vulnérabilités dans les produits HPE Aruba Networking (16 septembre 2026)
→ No new info (linked only)
Tier C
VulDB4d ago
CVE-2026-76681 | HPE EdgeConnect SD-WAN Orchestrator up to 9.4.10/9.5.8/9.6.3/9.7.0 API improper authorization
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
PublishedSep 15, 2026
Last enriched4d ago
Trending Score26
Source articles3
Independent3
Info Completeness7/14
Missing: epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-76672
Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Orchestrator
Trending: 28
MEDIUMCVE-2026-76706
Unauthenticated Information Disclosure in EdgeConnect SD-WAN Orchestrator API allows exposure of sensitive data
Trending: 27
MEDIUMCVE-2026-76695
Unauthenticated Buffer Overflow Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways
Trending: 27
HIGHCVE-2026-76680
Authenticated Server-Side Request Forgery Vulnerabilities Leading to Information Disclosure in EdgeConnect SD-WAN Orchestrator
Trending: 26
HIGHCVE-2026-76688
Authentication Bypass Vulnerabilities in the Web-Based Management Interface of EdgeConnect SD-WAN Orchestrator
Trending: 26

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 15, 2026
Discovered by ZDM
Sep 15, 2026