---
id: CVE-2026-76698
title: >-
  A command injection vulnerability exists in the web-based management interface
  of HPE Networking EdgeConnect SD-WAN Gateways
summary: >-
  A command injection vulnerability exists in the web-based management interface
  of HPE Networking EdgeConnect SD-WAN Gateways. An authenticated remote
  attacker with limited access privileges could exploit this vulnerability
  through specia…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-77
vendor: Hewlett Packard Enterprise (HPE)
product: EdgeConnect SD-WAN Gateways
affected:
  - edgeconnect_sd-wan_gateways >= 9.7.0.0 <= 9.7.0.0
  - edgeconnect_sd-wan_gateways >= 9.6.0.0 <= 9.6.3.1
  - edgeconnect_sd-wan_gateways >= 9.5.0.0 <= 9.5.8.1
  - edgeconnect_sd-wan_gateways >= 9.4.0.0 <= 9.4.8.2
published: '2026-09-15'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T15:17:15.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76698'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
epss: 0.04436
epssPercentile: 0.9103
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-22T14:12:18.045665Z'
ingestedAt: '2026-09-15T19:42:58.823Z'
---

## Overview

A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways. An authenticated remote attacker with limited access privileges could exploit this vulnerability through specially crafted input. Successful exploitation, under certain conditions, could result in the execution of arbitrary commands with elevated privileges or a denial-of-service condition on the affected appliance.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
