Remote Code Execution Vulnerability in EdgeConnect SD-WAN Orchestrator by HPE
CVE-2026-76704

5.5MEDIUM

Key Information:

Vendor

HP (HP)

Vendor
CVE Published:
15 September 2026

What is CVE-2026-76704?

A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator allows authenticated remote attackers to execute arbitrary script code in the victim's browser. If exploited, this could lead to unauthorized access to sensitive information, compromising the confidentiality and integrity of the data managed by the application.

Affected Version(s)

EdgeConnect SD-WAN Gateways 9.7.0

EdgeConnect SD-WAN Gateways 9.7.0

EdgeConnect SD-WAN Gateways 9.6.0 <= 9.6.3

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability was reported by m0x_noob to the HPE Networking Bug Bounty program.
.