---
id: CVE-2026-76701
title: >-
  A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN
  Gateways could allow an unauthenticated remote attacker to access sensitive
  information
summary: >-
  A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN
  Gateways could allow an unauthenticated remote attacker to access sensitive
  information. Successful exploitation could allow an attacker to retrieve
  information whi…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-306
vendor: Hewlett Packard Enterprise (HPE)
product: EdgeConnect SD-WAN Gateways
affected:
  - edgeconnect_sd-wan_gateways >= 9.7.0.0 <= 9.7.0.0
  - edgeconnect_sd-wan_gateways >= 9.6.0.0 <= 9.6.3.1
  - edgeconnect_sd-wan_gateways >= 9.5.0.0 <= 9.5.8.1
  - edgeconnect_sd-wan_gateways >= 9.4.0.0 <= 9.4.8.2
published: '2026-09-15'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T20:17:31.690'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76701'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T19:54:11.087829Z'
epss: 0.00394
epssPercentile: 0.30853
ingestedAt: '2026-09-15T19:42:58.821Z'
---

## Overview

A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
