CVE-2026-76697

Summary

A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.

Affected Software

VendorProductVersion RangeStatus
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.7.0.0 <= 9.7.0.0affected
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.6.0.0 <= 9.6.3.1affected
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.5.0.0 <= 9.5.8.1affected
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.4.0.0 <= 9.4.8.2affected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References