CVE-2026-76707

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
15/09/2026
Last modified:
28/09/2026

Description

A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of unauthorized access and elevated privileges when combined with other vulnerabilities.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:* 9.4.0 (including) 9.4.11 (excluding)
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:* 9.5.0 (including) 9.5.9 (excluding)
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:* 9.6.0 (including) 9.6.4 (excluding)
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.7.0:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:* 9.4.0.0 (including) 9.4.9.0 (excluding)
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:* 9.5.0.0 (including) 9.5.9.0 (excluding)
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:* 9.6.0.0 (including) 9.6.4.0 (excluding)
cpe:2.3:o:hpe:edgeconnect_operating_system:9.7.0.0:*:*:*:*:*:*:*