A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system. | |
| Title | Authenticated Arbitrary File Write Leading to Remote Code Execution in EdgeConnect SD-WAN Orchestrator | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2026-09-15T19:23:46.882Z
Reserved: 2026-08-19T16:11:34.861Z
Link: CVE-2026-76687
No data.
Status : Received
Published: 2026-09-15T20:17:50.683
Modified: 2026-09-15T20:17:50.683
Link: CVE-2026-76687
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.