Server-Side Request Forgery Vulnerability in HPE EdgeConnect SD-WAN Orchestrator
CVE-2026-76680

8.5HIGH

Key Information:

Vendor

HP (HP)

Vendor
CVE Published:
15 September 2026

What is CVE-2026-76680?

A vulnerability exists within the API of HPE EdgeConnect SD-WAN Orchestrator, enabling remote attackers with low privilege access to execute server-side request forgery (SSRF) attacks. By successfully exploiting this vulnerability, an attacker can access and enumerate sensitive information about the internal infrastructure of the EdgeConnect SD-WAN Orchestrator host, surpassing the limitations imposed by the user's current privilege level.

Affected Version(s)

EdgeConnect SD-WAN Gateways 9.7.0

EdgeConnect SD-WAN Gateways 9.7.0

EdgeConnect SD-WAN Gateways 9.6.0 <= 9.6.3

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Internal security research (HPE Networking).
.