---
id: CVE-2026-76681
title: >-
  A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an
  authenticated remote attacker with low privileges to access sensitive
  information beyond what is authorized by the user's existing privilege level
summary: >-
  A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an
  authenticated remote attacker with low privileges to access sensitive
  information beyond what is authorized by the user's existing privilege level.
  Successful e…
severity: high
cvss: 8.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'
cwe:
  - CWE-284
vendor: arubanetworks
product: edgeconnect_sd-wan_orchestrator
affected:
  - 'edgeconnect_sd-wan_orchestrator >= 9.4.0, < 9.4.11'
  - 'edgeconnect_sd-wan_orchestrator >= 9.5.0, < 9.5.9'
  - 'edgeconnect_sd-wan_orchestrator >= 9.6.0, < 9.6.4'
  - edgeconnect_sd-wan_orchestrator = 9.7.0
  - 'edgeconnect_operating_system >= 9.4.0.0, < 9.4.9.0'
  - 'edgeconnect_operating_system >= 9.5.0.0, < 9.5.9.0'
  - 'edgeconnect_operating_system >= 9.6.0.0, < 9.6.4.0'
  - edgeconnect_operating_system = 9.7.0.0
patched:
  - edgeconnect_sd-wan_orchestrator 9.6.4
  - edgeconnect_operating_system 9.6.4.0
published: '2026-09-15'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T12:56:52.870'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76681'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
epss: 0.00353
epssPercentile: 0.26319
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T19:55:03.679146Z'
ingestedAt: '2026-09-15T19:42:58.828Z'
---

## Overview

A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privileges to access sensitive information beyond what is authorized by the user's existing privilege level. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by EdgeConnect SD-WAN Orchestrator.

## Affected

- `edgeconnect_sd-wan_orchestrator >= 9.4.0, < 9.4.11`
- `edgeconnect_sd-wan_orchestrator >= 9.5.0, < 9.5.9`
- `edgeconnect_sd-wan_orchestrator >= 9.6.0, < 9.6.4`
- `edgeconnect_sd-wan_orchestrator = 9.7.0`
- `edgeconnect_operating_system >= 9.4.0.0, < 9.4.9.0`
- `edgeconnect_operating_system >= 9.5.0.0, < 9.5.9.0`
- `edgeconnect_operating_system >= 9.6.0.0, < 9.6.4.0`
- `edgeconnect_operating_system = 9.7.0.0`

## Remediation

Upgrade past the affected range:

- `edgeconnect_sd-wan_orchestrator 9.6.4`
- `edgeconnect_operating_system 9.6.4.0`
