Skip to content

Hewlett Packard Enterprise EdgeConnect SD-WAN Gateway: insecure permissions

High7.2CVE-2026-44878 · Published Jul 21, 2026 · updated Jul 23, 2026

A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful exploitation of this vulnerability could allow an attacker to access sensitive files and tamper with or delete system data.

Affected versions

PackageAffectedFixed in
EdgeConnect SD-WAN Gateway (ECOS)
Product
>= 9.4.0.0, <= 9.4.6.0No fix yet
>= 9.5.0.0, <= 9.5.6.0No fix yet
>= 9.6.0.0, <= 9.6.1.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-377, CWE-732

More Hewlett Packard Enterprise advisories

All Hewlett Packard Enterprise
Advisory
Hewlett Packard Enterprise EdgeConnect: information disclosure
Critical9.8Aug 4
Hewlett Packard Enterprise EdgeConnect SD-WAN Gateway (ECOS): command injection
High7.2Jul 21
Hewlett Packard Enterprise AOS-CX: buffer overflow
High7.2Jul 21
Hewlett Packard Enterprise AOS-CX: path traversal
High7.2Jul 21
Hewlett Packard Enterprise AOS-CX: buffer overflow
High8.8Jul 21
Hewlett Packard Enterprise HPE Networking Instant On: information disclosure
Medium6.5Jul 7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.