CVE-2026-76680
8.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Summary
Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | 9.7.0 <= 9.7.0 | affected |
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | 9.6.0 <= 9.6.3 | affected |
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | 9.5.0 <= 9.5.8 | affected |
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | 9.4.0 <= 9.4.10 | affected |
Weaknesses
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.