{"id":"CVE-2026-76680","title":"Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks","summary":"Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate inf…","severity":"high","cvss":8.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","cwe":["CWE-918"],"vendor":"Hewlett Packard Enterprise (HPE)","product":"EdgeConnect SD-WAN Gateways","affected":["edgeconnect_sd-wan_gateways >= 9.7.0 <= 9.7.0","edgeconnect_sd-wan_gateways >= 9.6.0 <= 9.6.3","edgeconnect_sd-wan_gateways >= 9.5.0 <= 9.5.8","edgeconnect_sd-wan_gateways >= 9.4.0 <= 9.4.10"],"published":"2026-09-15","updated":"2026-09-21","sourceUpdated":"2026-09-21T20:17:30.590","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76680","references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US","label":"security-alert@hpe.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-21T19:47:03.556475Z"},"epss":0.00285,"epssPercentile":0.21247,"ingestedAt":"2026-09-15T19:42:58.828Z","slug":"CVE-2026-76680","body":"## Overview\n\nVulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":46.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}