CVE-2026-76669

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
15/09/2026
Last modified:
25/09/2026

Description

Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:* 9.4.0 (including) 9.4.11 (excluding)
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:* 9.5.0 (including) 9.5.9 (excluding)
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:* 9.6.0 (including) 9.6.4 (excluding)
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.7.0:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:* 9.4.0.0 (including) 9.4.9.0 (excluding)
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:* 9.5.0.0 (including) 9.5.9.0 (excluding)
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:* 9.6.0.0 (including) 9.6.4.0 (excluding)
cpe:2.3:o:hpe:edgeconnect_operating_system:9.7.0.0:*:*:*:*:*:*:*