CVE-2026-76672
Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Orchestrator
Description
A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.
In plain language
AI Act nowThis flaw lets a logged-in low-permission user of EdgeConnect SD-WAN Gateways read secret connection keys, so businesses using it should act now.
Authenticated network-based sensitive information disclosure in EdgeConnect SD-WAN Gateways allows read-only users to retrieve hidden configuration data, including third-party API credentials, through a crafted request.
What to do now
- Check whether you run EdgeConnect SD-WAN Gateways and identify all accounts with read-only access.
- Limit management-system network access to trusted administrators and networks while the vendor provides a fix.
- No fixed version has been published; contact HPE for the remediation release and upgrade guidance.
- Rotate third-party API tokens and credentials stored in the system if untrusted users may have had read access.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:LAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-76672 and every CVE in our database. Create a free account — no credit card required.
Create Free Account