CVE-2026-76694

Summary

A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to escalate privileges beyond their authorized level, and execute arbitrary code on a vulnerable system.

Affected Software

VendorProductVersion RangeStatus
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.7.0.0 <= 9.7.0.0affected
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.6.0.0 <= 9.6.3.1affected
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.5.0.0 <= 9.5.8.1affected
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.4.0.0 <= 9.4.8.2affected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References