CVE-2026-76675

Summary

A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to execute arbitrary commands on the underlying operating system leading to complete system compromise.

Affected Software

VendorProductVersion RangeStatus
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.7.0.0 <= 9.7.0.0affected
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.6.0.0 <= 9.6.3.1affected
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.5.0.0 <= 9.5.8.1affected
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.4.0.0 <= 9.4.8.2affected

Weaknesses

References