Server-Side Request Forgery Vulnerability in HPE EdgeConnect SD-WAN Orchestrator
CVE-2026-76680
8.5HIGH
What is CVE-2026-76680?
A vulnerability exists within the API of HPE EdgeConnect SD-WAN Orchestrator, enabling remote attackers with low privilege access to execute server-side request forgery (SSRF) attacks. By successfully exploiting this vulnerability, an attacker can access and enumerate sensitive information about the internal infrastructure of the EdgeConnect SD-WAN Orchestrator host, surpassing the limitations imposed by the user's current privilege level.
Affected Version(s)
EdgeConnect SD-WAN Gateways 9.7.0
EdgeConnect SD-WAN Gateways 9.7.0
EdgeConnect SD-WAN Gateways 9.6.0 <= 9.6.3
