Remote Code Execution Vulnerability in EdgeConnect SD-WAN Orchestrator by HPE
CVE-2026-76704
5.5MEDIUM
What is CVE-2026-76704?
A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator allows authenticated remote attackers to execute arbitrary script code in the victim's browser. If exploited, this could lead to unauthorized access to sensitive information, compromising the confidentiality and integrity of the data managed by the application.
Affected Version(s)
EdgeConnect SD-WAN Gateways 9.7.0
EdgeConnect SD-WAN Gateways 9.7.0
EdgeConnect SD-WAN Gateways 9.6.0 <= 9.6.3
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability was reported by m0x_noob to the HPE Networking Bug Bounty program.
